First published: Tue Feb 25 2025(Updated: )
Improper Input Validation vulnerability in The Document Foundation LibreOffice allows Windows Executable hyperlink targets to be executed unconditionally on activation.This issue affects LibreOffice: from 24.8 before < 24.8.5.
Credit: security@documentfoundation.org
Affected Software | Affected Version | How to fix |
---|---|---|
LibreOffice Draw | >24.8<24.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0514 has a medium severity rating due to its improper input validation allowing unwanted execution of Windows Executables.
To fix CVE-2025-0514, update LibreOffice to version 24.8.5 or later.
CVE-2025-0514 affects LibreOffice versions from 24.8 up to but not including 24.8.5.
CVE-2025-0514 may allow attackers to execute Windows Executables without user consent when hyperlinks are activated.
CVE-2025-0514 specifically affects the Windows versions of LibreOffice.