Authorization Flaw in Apache OpenOffice Allows Unauthorized External Link Access
CVE-2025-64407

5.3MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
12 November 2025

What is CVE-2025-64407?

A missing authorization vulnerability in Apache OpenOffice allows crafted documents to include external links that load without user consent. This flaw can lead to unauthorized transmission of sensitive system information, including configuration settings and environment variables. Users running versions prior to 4.1.16 are at risk and should upgrade to mitigate this issue.

Affected Version(s)

Apache OpenOffice 0 <= 4.1.15

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thomas Rinsma of Codean Labs
.