CVE-2021-25631

In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be circumvented by manipulating the link so it doesn't match the denylist but results in ShellExecute attempting to launch an executable type.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

History

12 May 2021, 18:58

Type Values Removed Values Added
References (MISC) https://positive.security/blog/url-open-rce#open-libreoffice - (MISC) https://positive.security/blog/url-open-rce#open-libreoffice - Exploit, Third Party Advisory
References (MISC) https://www.libreoffice.org/about-us/security/advisories/cve-2021-25631/ - (MISC) https://www.libreoffice.org/about-us/security/advisories/cve-2021-25631/ - Vendor Advisory
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : 9.3
v3 : 8.8
CPE cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

03 May 2021, 13:52

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-03 12:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-25631

Mitre link : CVE-2021-25631

CVE.ORG link : CVE-2021-25631


JSON object : View

Products Affected

libreoffice

  • libreoffice
CWE
NVD-CWE-Other CWE-184

Incomplete List of Disallowed Inputs