In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade libreoffice
to version 24.8.5.1 or higher.
Affected versions of this package are vulnerable to External Control of File Name or Path in the CSysShExec::execute()
function in win32/SysShExec.cxx
, which may access and execute non-file URIs behind hyperlinks using ShellExecute
. An attacker who can convince a user to follow a malicious hyperlink in a document can cause an arbitrary executable to be run.
Note: This is only exploitable on Windows.