Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-3524

29
FAUCET Score

CVE-2014-3524 is a critical vulnerability affecting Apache OpenOffice prior to version 4.1.1, and also impacts LibreOffice. It allows remote attackers to execute arbitrary commands and potentially cause other unspecified damage through a specially crafted Calc spreadsheet. With a CVSS score of 9.3, this vulnerability is highly severe, requiring medium attack complexity but allowing for complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high FAUCET Risk Score indicates significant potential danger.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.1.1CPE matchmatch criteria
cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*
< 4.2.6CPE matchmatch criteria
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*
>= 4.3.0, < 4.3.1CPE matchmatch criteria
cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

9.3HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
14.60%
Probability of exploitation in next 30 days
EPSS Percentile
96.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1460 is in the 80th percentile among its peer group of 8,918 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

asteriskpatch availablevia llm_extracted
Fixed in: 4.2.6-secfix/4.3.1
View patch
check_pointpatch availablevia llm_extracted
Fixed in: 4.2.6-secfix/4.3.1
View patch
denopatch availablevia llm_extracted
Fixed in: 4.1.1
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 4.1.1
View patch
nessuspatch availablevia llm_extracted
Fixed in: 4.1.1
postgresqlpatch availablevia llm_extracted
Fixed in: 4.1.1
View patch

Vendor Advisories (7)

redhatCVE-2014-3524Moderate

libreoffice/openoffice.org: CSV command injection and DDE formulas

Aug 21, 2014
asteriskllm-asterisk-73ab24cacf89d4b0

CSV Command Injection and DDE formulas

check_pointllm-check_point-faa2ee5bdc6500da

CSV Command Injection and DDE formulas

denollm-deno-072ca98c9b489665

Calc Command Injection Vulnerability in Apache OpenOffice

postgresqlllm-postgresql-9f06fce30b26937c

Calc Command Injection Vulnerability in Apache OpenOffice

libreofficellm-libreoffice-cb4dfe3e5346ac7f

Calc Command Injection Vulnerability in Apache OpenOffice

nessusllm-nessus-b147508c0ad173e4

Calc Command Injection Vulnerability in Apache OpenOffice

References

blog.documentfoundation.org / 2014/08/28/libreoffice-4-3-1-fresh-announced
Vendor Advisory
secunia.com / advisories/59600
Broken Link
secunia.com / advisories/59877
Broken Link
secunia.com / advisories/60235
Broken Link
exchange.xforce.ibmcloud.com / vulnerabilities/95421
Third Party AdvisoryVDB Entry
security.gentoo.org / glsa/201603-05
Third Party Advisory
openoffice.org / security/cves/CVE-2014-3524.html
Vendor Advisory
securityfocus.com / archive/1/533200/100/0/threaded
Broken LinkThird Party AdvisoryVDB Entry
securityfocus.com / bid/69351
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030755
Broken LinkThird Party AdvisoryVDB Entry