CVE-2021-25631

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:55

Type Values Removed Values Added
References () https://positive.security/blog/url-open-rce#open-libreoffice - Exploit, Third Party Advisory () https://positive.security/blog/url-open-rce#open-libreoffice - Exploit, Third Party Advisory
References () https://www.libreoffice.org/about-us/security/advisories/cve-2021-25631/ - Vendor Advisory () https://www.libreoffice.org/about-us/security/advisories/cve-2021-25631/ - Vendor Advisory

Information

Published : 2021-05-03 12:15

Updated : 2024-11-21 05:55


NVD link : CVE-2021-25631

Mitre link : CVE-2021-25631

CVE.ORG link : CVE-2021-25631


JSON object : View

Products Affected

libreoffice

  • libreoffice
CWE
CWE-184

Incomplete List of Disallowed Inputs

NVD-CWE-Other