CVE-2019-9847 is a critical vulnerability in LibreOffice for Windows and macOS versions prior to 6.1.6 and 6.2.3. It allows an attacker to craft documents with malicious hyperlinks that, when clicked, unconditionally launch executable files located on the victim's system. This vulnerability has a high CVSS score of 7.8, indicating a low attack complexity and the potential for complete compromise of confidentiality, integrity, and availability if a user is tricked into activating the malicious hyperlink. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, the risk remains due to the ease of exploitation once a user interaction occurs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.1.6CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.2.3CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.