CVE-2024-3044
LibreOffice vulnerability analysis and mitigation

Overview

CVE-2024-3044 affects LibreOffice's graphic on-click binding functionality. The vulnerability was discovered on May 14, 2024, and allows an attacker to create a document that executes built-in LibreOffice scripts without prompting when a user clicks on a graphic. The vulnerability affects various versions of LibreOffice prior to versions 7.6.7 and 24.2.3 (LibreOffice Advisory).

Technical details

The vulnerability stems from LibreOffice's feature that supports binding scripts to click events on graphics. In affected versions, there are scenarios where built-in scripts, which were previously considered trusted but are now deemed untrusted, can be executed without warning when a user clicks on a document with such on-click handlers. The CVSS v3.1 base score is 6.5 (Medium), with a vector string of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L (NVD).

Impact

If exploited, this vulnerability could allow an attacker to execute arbitrary scripts built into LibreOffice when a user clicks on a specially crafted graphic within a document. This could potentially lead to unauthorized script execution and compromise the security of the affected system (Ubuntu Security).

Mitigation and workarounds

The vulnerability has been fixed in LibreOffice versions 7.6.7 and 24.2.3. In the fixed versions, the user's explicit macro execution permissions for the document, determined at load time, are used for these handlers. Users are strongly recommended to upgrade to these versions or later to mitigate the vulnerability (LibreOffice Advisory).

Community reactions

The vulnerability was discovered and reported by Amel Bouziane-Leblond, with Collabora Productivity providing the fix. Multiple Linux distributions have released security updates to address this vulnerability, including Ubuntu, Debian, and Fedora (Debian LTS, Fedora Update).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management