First published: Tue Oct 11 2016(Updated: )
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan Horse application (or user) running with administrative privilege. Any installer with the unquoted search path vulnerability becomes a delayed trigger for the exploit.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OpenOffice | <=4.1.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6803 is an installer defect known as an unquoted Windows search path vulnerability that affected the Apache OpenOffice before 4.1.3 installers for Windows.
The severity of CVE-2016-6803 is critical with a CVSS score of 7.8.
The affected software by CVE-2016-6803 is Apache OpenOffice before version 4.1.3 for Windows.
CVE-2016-6803 does not directly affect Microsoft Windows, but the vulnerability can be exploited on a PC with a previously infected Trojan Horse application running with administrative privilege.
To fix CVE-2016-6803, update Apache OpenOffice to version 4.1.3 or later.