CVE-2023-6186

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.

In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.3 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
Document Fdn.CNA
8.3 HIGH
ADJACENT_NETWORK
LOW
LOW
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
libreofficelibreoffice
7.5.0 ≤
𝑥
< 7.5.9
libreofficelibreoffice
7.6.0 ≤
𝑥
< 7.6.4
debiandebian_linux
11.0
debiandebian_linux
12.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libreoffice
bullseye
1:7.0.4-4+deb11u10
fixed
bullseye (security)
1:7.0.4-4+deb11u11
fixed
bookworm
4:7.4.7-1+deb12u5
fixed
bookworm (security)
4:7.4.7-1+deb12u5
fixed
sid
4:24.8.4-1
fixed
trixie
4:24.8.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libreoffice
mantic
Fixed 4:7.6.4-0ubuntu0.23.10.1
released
lunar
Fixed 4:7.5.9-0ubuntu0.23.04.1
released
jammy
Fixed 1:7.3.7-0ubuntu0.22.04.4
released
focal
Fixed 1:6.4.7-0ubuntu0.20.04.9
released
bionic
ignored
xenial
ignored
trusty
ignored