First published: Mon May 03 2021(Updated: )
In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.
Credit: security@documentfoundation.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libreoffice Libreoffice | >=7.0.0<7.0.5 | |
Libreoffice Libreoffice | >=7.1.0<7.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25631 is a vulnerability in the LibreOffice 7-1 series in versions prior to 7.1.2 and in the 7-0 series in versions prior to 7.0.5.
CVE-2021-25631 has a severity rating of 8.8 (critical).
CVE-2021-25631 allows the circumvention of the denylist in LibreOffice, potentially enabling the execution of malicious code.
The LibreOffice 7-1 series in versions prior to 7.1.2 and the 7-0 series in versions prior to 7.0.5 are affected by CVE-2021-25631.
CVE-2021-25631 can be exploited by manipulating a link to bypass the denylist and execute arbitrary code using ShellExecute.