Code Execution Vulnerability in Apache OpenOffice Installer for Windows
CVE-2016-6804
7.8HIGH
Summary
The installer for Apache OpenOffice, particularly versions before 4.1.3 (including certain instances branded as OpenOffice.org), contains a serious flaw that permits the execution of arbitrary code with elevated privileges. This vulnerability is triggered when the installer is executed from a compromised directory where a malicious dynamic-link library file has been planted. Due to this design weakness, an attacker could leverage this exploitation method to gain unauthorized access and control over the affected system.
Affected Version(s)
Apache OpenOffice 4.0.0 to 4.1.2
Apache OpenOffice older releases are also affected, including some branded as OpenOffice.org
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved