vulnerability

FreeBSD: VID-a86f9189-fdd9-11ef-91ff-b42e991fc52e (CVE-2025-1080): libreoffice -- Macro URL arbitrary script execution

Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
Mar 10, 2025
Added
Mar 12, 2025
Modified
Jan 27, 2026

Description

[email protected] reports: LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1.

Solution

freebsd-upgrade-package-libreoffice
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.