HomeSecurityVulnerabilities in LibreOffice and OpenOffice allow malware execution

Vulnerabilities in LibreOffice and OpenOffice allow malware execution

Security researchers have uncovered a serious vulnerability in the popular office software LibreOffice and Apache OpenOfficethat could allow malicious code to be executed upon opening an infected spreadsheet file. This security flaw, which is related to the “LibreOffice vulnerabilities,” does not warn the user before executing a macro, making it particularly dangerous.

See also: LibreOffice vulnerability allows execution of arbitrary scripts

Article Image: LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

The attack exploits the Java support offered by the programs. When this is enabled, the malicious spreadsheet can execute the attacker's code without any warning. Although so far the attack has only been presented as a proof of concept and there are no reports of its use in real attacks, the potential for exploitation is worrying.

LibreOffice has already addressed the vulnerability, reporting it as CVE-2026-63277, with updates released on October 5. Users are urged to upgrade to versions 26.2.5 or 26.8.0, as earlier versions are vulnerable. In contrast, Apache OpenOffice has not yet patched the corresponding vulnerability, reported as CVE-2026-59265. All versions up to and including 4.1.16 are affected, and the fix is ​​expected in version 4.1.17, which is still in testing.

Apache OpenOffice users can temporarily protect themselves by disabling Java in the program's settings or by avoiding opening spreadsheets from untrusted sources. The attack exploits a combination of features that work normally on their own. A Calc spreadsheet can contain a "database area," which pulls data from an external source and automatically refreshes it.

This source can be a separate database file (ODB), which is specified by a web address in the spreadsheet.

See also: OnePlus vulnerabilities allow malicious apps to gain root access

Article image: New macOS malware turns stolen browsers into attacker-controlled sessions

When the spreadsheet is opened, the area refreshes and the program downloads the ODB from the web address. The ODB can specify a Java Database Connectivity (JDBC) driver and indicate where the driver code is located, which can be a JAR file or hosted on a remote server. The program then downloads the JAR and launches the driver, which is the attacker's malicious code, within the program itself.

The security issue is that these features, combined, allow code execution without prompting the user to trust the document, as is usually the case before running a macro. In the proof of concept, the wizard simply opens the Calculator application, a harmless action, but the same path can execute any Java code the attacker chooses.

The researchers tested the attack on Windows and Linux, confirming that it is not tied to a specific operating system. In their demonstration, the malicious files were located on the same machine for convenience, but in a real attack, the database file and code would be placed on a server controlled by the attacker.

The vulnerability in LibreOffice was independently reported by Rick de Jager of the V12 security team and by Thomas Rinsma and Edoardo Geraci of Codean Labs. Apache OpenOffice credits Codean Labs for the vulnerability. The V12 team has published a proof of concept for both programs, and Caolán McNamara of Collabora Productivity wrote the fix for LibreOffice.

See also: Microsoft Office 2019 Mac: Documents will not be editable

Vulnerabilities in LibreOffice and OpenOffice allow malware execution

The discovery of this vulnerability highlights the importance of continuously monitoring and updating office software, as well as the need for increased user awareness of the potential threats they may face when using these tools. Organizations and users should be particularly careful with the files they open and ensure they are using the latest versions of software to protect themselves from such vulnerabilities.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS