CVE-2018-16858 is a critical directory traversal vulnerability affecting LibreOffice versions prior to 6.0.7 and 6.1.3. This flaw allows an attacker to craft a malicious document that, when opened, executes arbitrary Python macros from any filesystem location relative to the LibreOffice installation. With a CVSS score of 9.8, this vulnerability presents a high risk of complete compromise (confidentiality, integrity, and availability) due to its network-based attack vector and low attack complexity, requiring no user interaction. While not listed on CISA's KEV catalog, exploit modules are publicly available in Metasploit, and the vulnerability has garnered significant community discussion and media coverage, indicating active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.0.7CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* | ||
>= 6.1.0, < 6.1.3CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libreoffice: Arbitrary python functions in arbitrary modules on the filesystem can be executed without warning
Feb 1, 2019Directory traversal flaw in script execution
Directory traversal flaw in script execution