Unchecked Script Execution Vulnerability Affects LibreOffice Users
CVE-2024-3044

Currently unrated

Key Information:

Vendor
CVE Published:
14 May 2024

What is CVE-2024-3044?

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.

Affected Version(s)

LibreOffice 7.6 < 7.6.7

LibreOffice 24.2 < 24.2.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to Amel Bouziane-Leblond for for finding and reporting this issue.
.