Potential Vulnerability in Certificate Validation User Interface of LibreOffice
CVE-2024-6472

7.8HIGH

Key Information:

Vendor
CVE Published:
5 August 2024

What is CVE-2024-6472?

LibreOffice contains a vulnerability in its certificate validation user interface that impacts the handling of signed macros. When a document containing a signed macro is opened, the application generates a warning if the macro's verification fails. However, previous versions allowed users to misinterpret the failure message and mistakenly enable the macros regardless of the verification status. This behavior can lead to potential security risks, as malicious code could be executed if the user overrides the warning. The flaw affects LibreOffice versions prior to 24.2.5, requiring immediate attention to maintain secure document handling.

Affected Version(s)

LibreOffice 24.2 < 24.2.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to OpenSource Security GmbH on behalf of the German Federal Office for Information Security
.