CVE-2014-3524 is a critical vulnerability affecting Apache OpenOffice prior to version 4.1.1, and also impacts LibreOffice. It allows remote attackers to execute arbitrary commands and potentially cause other unspecified damage through a specially crafted Calc spreadsheet. With a CVSS score of 9.3, this vulnerability is highly severe, requiring medium attack complexity but allowing for complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high FAUCET Risk Score indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.1CPE matchmatch criteria | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* | ||
< 4.2.6CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* | ||
>= 4.3.0, < 4.3.1CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libreoffice/openoffice.org: CSV command injection and DDE formulas
Aug 21, 2014CSV Command Injection and DDE formulas
CSV Command Injection and DDE formulas
Calc Command Injection Vulnerability in Apache OpenOffice
Calc Command Injection Vulnerability in Apache OpenOffice
Calc Command Injection Vulnerability in Apache OpenOffice
Calc Command Injection Vulnerability in Apache OpenOffice