CVE-2024-6472
NixOS vulnerability analysis and mitigation

Overview

A security vulnerability (CVE-2024-6472) was discovered in LibreOffice's certificate validation user interface. The issue affects LibreOffice versions from 24.2 before 24.2.5. When a document containing a signed macro is opened, LibreOffice displays a warning before execution. Previously, if signature verification failed, users could potentially misunderstand the failure and choose to enable potentially malicious macros anyway (LibreOffice Advisory).

Technical details

The vulnerability relates to the handling of signed macros, which are scripts digitally signed by developers using cryptographic signatures. The issue specifically concerns the behavior when signature verification fails, where users could override security warnings even in cases where the certificate validation had failed. This created a potential security risk by allowing execution of macros with invalid signatures (LibreOffice Advisory). The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD).

Impact

The vulnerability could potentially allow the execution of malicious macros even when their digital signatures fail verification, potentially compromising system security. This could lead to high impacts on confidentiality, integrity, and availability of the affected system if exploited (NVD).

Exploitability

The vulnerability requires user interaction and local access to be exploited. An attacker would need to convince a user to open a document containing a macro with an invalid signature, and the user would need to explicitly choose to trust the invalid signature (NVD).

Mitigation and workarounds

The vulnerability has been fixed in LibreOffice 24.2.5. In the updated version, when running in High Macro Security mode (the default setting), LibreOffice automatically disables macros that fail the certificate check. Users are strongly recommended to upgrade to version 24.2.5 to receive this security enhancement (LibreOffice Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

libreoffice: 4:7.4.7-1+deb12u4

Fixed

bullseye

libreoffice: 1:7.0.4-4+deb11u10

Fixed

sid

libreoffice: 4:24.2.5-1

Fixed

trixie

libreoffice: 4:24.2.5-1

Fixed

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86993MEDIUM5.9
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86996MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86995MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86994MEDIUM5.3
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026
CVE-2026-86085MEDIUM5.1
  • NixOS logoNixOS
  • n8n
NoYesSep 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management