LibreOffice: Windows vulnerability affects links in documents, patch available
LibreOffice is a popular open source Office suite that is used by millions of users as an alternative to Microsoft Office. We have followed LibreOffice for almost 15 years here on this blog. The developers of the free tool have just confirmed a new security issue in LibreOffice that affects users on Windows only.
The details:
- LibreOffice 24.8 to 24.8.4 are affected by the issue.
- Attackers may exploit the issue to launch executable files when users activate links in LibreOffice documents.
- The severity is high.
About the vulnerability
LibreOffice documents may contain links. Users may open the links directly by holding down the Ctrl-key before left-clicking on a link. The Office suite includes protections against launching executable files directly from links.
How it is triggered: users do need to actively Ctrl-click on links in LibreOffice documents to trigger the vulnerability.
The vulnerability CVE-2025-0514 is a bypass that allows attackers to create specially crafted documents that contain links that may run executable files on the target system.
LibreOffice explains that the integrated "mechanism could be bypassed by use of non-file URLs that could be interpreted by ShellExecute as Windows file paths".
Good to know: ShellExecute is a Windows function for launching applications.
Solution: install the update to LibreOffice 24.8.5
A new version of LibreOffice was released last week that fixes the security issue by blocking means to circumvent the link protections.
LibreOffice 24.8.5 is available and users are encouraged to install the new version on their devices, especially if they run the software on a Windows PC.
Downloads are provided on the official project website. Note that LibreOffice 24.8.x is the previous stable branch of the open Office suite. You may also download and install LibreOffice 25.2.1, which is the current stable version.
Note that the developers do not mention LibreOffice 25.2.1 in the context of the vulnerability. This suggests that the latest version is also -- likely -- not affected by the vulnerability.
RECOMMENDED NEWS
Windows 11 Development: overview of the November 2023 changes
Microsoft announced and introduced several important changes in November 2023. The company released...
Microsoft is removing a tool from Windows 11 that you may have never used
Microsoft plans to remove several long-standing apps from its Windows 11 operating system. Besides ...
The first Windows security updates of 2024 are here
Welcome to the Microsoft Windows January 2024 security updates overview. It is the first Patch Day ...
How to enable Stolen Device Protection on iPhone
Apple released iOS 17.3 this week, which brought an important security feature. Here's how to enabl...
Overview of the March 2024 Windows Security Updates
Microsoft released security updates for all supported versions of its Windows operating system and ...
FBI Seizes Cracked.io and Nulled.to in Major Cybercrime Crackdown
The FBI has seized the domains of Cracked.io and Nulled.to, two well-known hacking forums associate...
Comments on "LibreOffice: Windows vulnerability affects links in documents, patch available" :