LibreOffice Vulnerability in URI Scheme Leading to Macro Execution
CVE-2025-1080

7.2HIGH

Key Information:

Vendor
CVE Published:
4 March 2025

What is CVE-2025-1080?

A vulnerability in LibreOffice's handling of Office URI Schemes can allow attackers to craft a malicious link that invokes internal macros with arbitrary arguments. This issue arises when utilizing the 'vnd.libreoffice.command' scheme, which enables deeper integration with web resources like MS SharePoint servers. When a user clicks on such a link in a browser, it can execute potentially harmful macros in LibreOffice, posing significant security risks to users of the affected versions. Prompt updates to LibreOffice versions are recommended to mitigate this risk.

Affected Version(s)

LibreOffice 24.8

LibreOffice 25.2

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to Amel Bouziane-Leblond for finding and reporting this issue.
.