Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-6804

27
FAUCET Score

CVE-2016-6804 is a high-severity arbitrary code execution vulnerability affecting the Apache OpenOffice installer for Windows (versions prior to 4.1.3). An attacker could exploit this by pre-poisoning the installer's execution directory with a malicious DLL, leading to elevated privilege execution. While the CVSS score is 7.8 (High), indicating significant impact on confidentiality, integrity, and availability, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.1.3CPE matchmatch criteria
cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.02%
Probability of exploitation in next 30 days
EPSS Percentile
86.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0302 is in the 87th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

denopatch availablevia llm_extracted
Fixed in: 4.1.3
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 4.1.3
View patch
nessuspatch availablevia llm_extracted
Fixed in: 4.1.3
postgresqlpatch availablevia llm_extracted
Fixed in: 4.1.3
View patch

Vendor Advisories (4)

denollm-deno-255e1ae7d0bd583e

Windows Installer Execution of Arbitrary Code with Elevated Privileges

postgresqlllm-postgresql-41b97dfdb1e57568

Windows Installer Execution of Arbitrary Code with Elevated Privileges

libreofficellm-libreoffice-9fada15f5b2d3f71

Windows Installer Execution of Arbitrary Code with Elevated Privileges

nessusllm-nessus-faa3802c6c9d61ad

Windows Installer Execution of Arbitrary Code with Elevated Privileges

References

openoffice.org / security/cves/CVE-2016-6804.html
Vendor Advisory
securityfocus.com / bid/93774
Third Party AdvisoryVDB Entry
securitytracker.com / id/1037016
Third Party AdvisoryVDB Entry