VulnerabilityModified
CVE-2018-6871
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
CRITICAL 9.8EPSS 22.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 22.80% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- libreoffice/libreoffice · debian/debian linux · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- cve@mitre.org
References
- https://access.redhat.com/errata/RHSA-2018:0418Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0517Third Party Advisory
- https://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-5-4-5&id=a916fc0c0e0e8b10cb4158fa0fa173fe205d434aPatch, Third Party Advisory
- https://github.com/jollheef/libreoffice-remote-arbitrary-file-disclosureExploit, Third Party Advisory
- https://usn.ubuntu.com/3579-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4111Third Party Advisory
- https://www.exploit-db.com/exploits/44022/Exploit, Third Party Advisory, VDB Entry
- https://www.libreoffice.org/about-us/security/advisories/cve-2018-1055/Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0418Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0517Third Party Advisory
- https://cgit.freedesktop.org/libreoffice/core/commit/?h=libreoffice-5-4-5&id=a916fc0c0e0e8b10cb4158fa0fa173fe205d434aPatch, Third Party Advisory
- https://github.com/jollheef/libreoffice-remote-arbitrary-file-disclosureExploit, Third Party Advisory
- https://usn.ubuntu.com/3579-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4111Third Party Advisory
- https://www.exploit-db.com/exploits/44022/Exploit, Third Party Advisory, VDB Entry
- https://www.libreoffice.org/about-us/security/advisories/cve-2018-1055/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.