CVE-2018-10583 is an information disclosure vulnerability affecting LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5. It allows an attacker to automatically initiate an SMB connection to a remote server by embedding a malicious link within an ODT document, potentially revealing the user's IP address and other network information. With a CVSS score of 7.5 (HIGH), this vulnerability has a low attack complexity and requires no user interaction, making it a significant risk for information exposure. While not actively exploited in the wild (KEV: No), exploit code is publicly available via Metasploit and ExploitDB, indicating a high potential for exploitation. Despite its high FAUCET Risk Score of 99/100, there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.3CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:6.0.3:*:*:*:*:*:*:* | ||
4.1.5CPE matchmatch criteria | cpe:2.3:a:apache:openoffice:4.1.5:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
libreoffice: Information disclosure via SMB connection embedded in malicious file
May 1, 2018Information disclosure via SMB link embedded in ODF document
Information disclosure via SMB link embedded in ODF document