
Cloud Vulnerability DB
A community-led vulnerabilities database
A security vulnerability (CVE-2024-6472) was discovered in LibreOffice's certificate validation user interface. The issue affects LibreOffice versions from 24.2 before 24.2.5. When a document containing a signed macro is opened, LibreOffice displays a warning before execution. Previously, if signature verification failed, users could potentially misunderstand the failure and choose to enable potentially malicious macros anyway (LibreOffice Advisory).
The vulnerability relates to the handling of signed macros, which are scripts digitally signed by developers using cryptographic signatures. The issue specifically concerns the behavior when signature verification fails, where users could override security warnings even in cases where the certificate validation had failed. This created a potential security risk by allowing execution of macros with invalid signatures (LibreOffice Advisory). The vulnerability has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (NVD).
The vulnerability could potentially allow the execution of malicious macros even when their digital signatures fail verification, potentially compromising system security. This could lead to high impacts on confidentiality, integrity, and availability of the affected system if exploited (NVD).
The vulnerability requires user interaction and local access to be exploited. An attacker would need to convince a user to open a document containing a macro with an invalid signature, and the user would need to explicitly choose to trust the invalid signature (NVD).
The vulnerability has been fixed in LibreOffice 24.2.5. In the updated version, when running in High Macro Security mode (the default setting), LibreOffice automatically disables macros that fail the certificate check. Users are strongly recommended to upgrade to version 24.2.5 to receive this security enhancement (LibreOffice Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."