{"id":37259,"date":"2025-02-28T10:09:29","date_gmt":"2025-02-28T09:09:29","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=37259"},"modified":"2025-02-28T10:09:29","modified_gmt":"2025-02-28T09:09:29","slug":"vulnerability-cve-2025-0514-in-libreoffice-fix-with-libreoffice-24-8-5","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2025\/02\/28\/vulnerability-cve-2025-0514-in-libreoffice-fix-with-libreoffice-24-8-5\/","title":{"rendered":"Vulnerability CVE-2025-0514 in LibreOffice &#8211; Fix with LibreOffice 24.8.5"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"margin: 0px 10px 0px 0px; display: inline; float: left;\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2012\/07\/Office1.jpg\" width=\"55\" height=\"60\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2025\/02\/28\/schwachstelle-cve-2025-0514-in-libreoffice-fix-mit-libreoffice-24-8-5\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]The LibreOffice developers have released LibreOffice 24.8.5 to close a link vulnerability CVE-2025-0514. The vulnerability could allow links to be abused.<\/p>\n<p><!--more--><\/p>\n<h2>The vulnerability CVE-2025-0514<\/h2>\n<p>The vulnerability <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-0514\" target=\"_blank\" rel=\"noopener\">CVE-2025-0514<\/a> is due to insufficient input validation in LibreOffice. This allows unconditional execution of Windows hyperlink executable targets upon activation. This issue affects LibreOffice: from 24.8 before &lt; 24.8.5. The vulnerability has been assigned a CVSS 4.0 index of 7.2 (High).<\/p>\n<h2>Fix with LibreOffice 24.8.5<\/h2>\n<p>The LibreOffice developers have published a <a href=\"https:\/\/www.libreoffice.org\/about-us\/security\/advisories\/cve-2025-0514\/\" target=\"_blank\" rel=\"noopener\">security advisory for CVE-2025-051<\/a> and write that LibreOffice allows, that hyperlinks in a document can be activated by CTRL+click.<\/p>\n<p>On Windows, the link can be passed to the system's ShellExecute function for editing. LibreOffice uses a mechanism to block paths to executable targets for ShellExecute to prevent attempts to start executable files.<\/p>\n<p>In LibreOffice versions &lt; 24.8.5, this mechanism could be bypassed by using non-file URLs that could be interpreted by <em>ShellExecute<\/em> as Windows file paths. Attackers could therefore have executed arbitrary commands.<\/p>\n<p>This bypass has been blocked in the corrected versions. All Windows users are recommended to update to LibreOffice &gt;= 24.8.5.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]The LibreOffice developers have released LibreOffice 24.8.5 to close a link vulnerability CVE-2025-0514. The vulnerability could allow links to be abused.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,580,1547],"tags":[1004,69],"class_list":["post-37259","post","type-post","status-publish","format-standard","hentry","category-office","category-security","category-software","tag-libreoffice","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/37259","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=37259"}],"version-history":[{"count":1,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/37259\/revisions"}],"predecessor-version":[{"id":37260,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/37259\/revisions\/37260"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=37259"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=37259"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=37259"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}