CVE-2024-3044: Graphic on-click binding allows unchecked script execution
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3044?
CVE-2024-3044 is considered a high severity vulnerability due to its potential for unchecked script execution.
How do I fix CVE-2024-3044?
To fix CVE-2024-3044, update LibreOffice to the latest versions specified in the advisory for your distribution.
Which versions of LibreOffice are affected by CVE-2024-3044?
CVE-2024-3044 affects multiple versions of LibreOffice, including 6.4.7 and 7.3.7 on Ubuntu.
Can CVE-2024-3044 be exploited remotely?
Yes, CVE-2024-3044 can be exploited by an attacker creating a malicious document that executes scripts without prompting the user.
Is there a way to mitigate CVE-2024-3044 before a patch is applied?
Temporarily, users should avoid opening LibreOffice documents from untrusted sources to mitigate the risks of CVE-2024-3044.