CVE-2025-64406
Homebrew vulnerability analysis and mitigation

Overview

CVE-2025-64406 is an out-of-bounds write vulnerability in Apache OpenOffice that allows an attacker to craft a malicious document — specifically during CSV import — that can crash the program or corrupt other memory areas. It affects Apache OpenOffice through version 4.1.15, and was disclosed on November 11–12, 2025. The vulnerability was discovered, reported, and fixed by Damjan Jovanovic. It carries a CVSS v3.1 base score of 4.3 (Medium) (OpenOffice Advisory, oss-security).

Technical details

The root cause is an out-of-bounds write (CWE-787) triggered during the CSV import process in Apache OpenOffice. An attacker can craft a specially formatted CSV document that, when opened by a victim, causes the application to write data outside the bounds of an allocated memory buffer, potentially corrupting adjacent memory regions. Exploitation requires user interaction — the victim must open the malicious document — and no authentication or special privileges are needed on the attacker's side. No public proof-of-concept exploit code has been identified (oss-security, OpenOffice Advisory).

Impact

Successful exploitation can cause Apache OpenOffice to crash (denial of service) or corrupt memory in adjacent areas, potentially leading to unexpected application behavior. The primary impact is availability loss (application crash), with limited confidentiality or integrity impact based on the CVSS assessment. In edge cases, memory corruption could theoretically be leveraged for further exploitation, though no such scenario has been demonstrated publicly (OpenOffice Advisory, oss-security).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation as of the time of disclosure. The vulnerability requires user interaction (opening a malicious document), which limits its attack surface. The EPSS score is approximately 0.118%, indicating a low probability of exploitation in the near term. CVE-2025-64406 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (OpenOffice Advisory, Feedly).

Exploitation steps

  1. Craft malicious document: Create a specially formatted CSV file designed to trigger an out-of-bounds write during Apache OpenOffice's CSV import routine.
  2. Deliver the document: Distribute the malicious CSV file to the target via email attachment, file sharing, or a malicious download link.
  3. Social engineering: Convince the victim to open the file using Apache OpenOffice (versions through 4.1.15).
  4. Trigger the vulnerability: When the victim opens the CSV file, the out-of-bounds write is triggered during the import process, causing the application to crash or corrupt adjacent memory regions.
  5. Achieve objective: At minimum, the attacker achieves denial of service (application crash); in more advanced scenarios, memory corruption could potentially be leveraged for further exploitation (oss-security, OpenOffice Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited CSV files received via email or file transfer, particularly from unknown senders.
  • Process: Apache OpenOffice process (soffice, soffice.bin) crashing unexpectedly or generating crash dump files after opening a CSV document.
  • Logs: Application crash logs or core dumps associated with OpenOffice's CSV import module; error messages referencing memory access violations or segmentation faults in OpenOffice logs.

Mitigation and workarounds

The primary remediation is to upgrade Apache OpenOffice to version 4.1.16, which contains the fix for this vulnerability. Users unable to upgrade immediately should exercise caution when opening CSV files from untrusted or unknown sources, and implement email and file transfer scanning to detect potentially malicious documents. Qualys scanner detection ID 385947 can be used to identify vulnerable installations (OpenOffice Advisory, Apache Mailing List).

Community reactions

The vulnerability was part of a broader set of seven security flaws fixed in Apache OpenOffice 4.1.16, which received coverage from security news outlets including SecurityOnline, CyberPress, and CyberSecurityNews. Community discussion was noted on Bluesky and oss-security mailing lists shortly after disclosure. Coverage generally characterized the update as important for users still relying on Apache OpenOffice, with recommendations to upgrade promptly (SecurityOnline, CyberPress, CyberSecurityNews).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-73896MEDIUM6.5
  • Homebrew logoHomebrew
  • helidon
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management