CVE-2023-6186: Link targets allow arbitrary script execution
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.
In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6186?
CVE-2023-6186 has a medium severity rating allowing execution of macros without warning.
How do I fix CVE-2023-6186?
To fix CVE-2023-6186, update LibreOffice to version 7.5.9 or 7.6.4 or higher.
What versions of LibreOffice are affected by CVE-2023-6186?
CVE-2023-6186 affects LibreOffice versions prior to 7.5.9 and versions prior to 7.6.4.
Can CVE-2023-6186 be exploited remotely?
Yes, CVE-2023-6186 can potentially be exploited remotely through malicious documents.
What is the impact of CVE-2023-6186 on users?
Users of LibreOffice with CVE-2023-6186 may experience unauthorized macro execution leading to potential data loss or compromise.