LibreOffice and OpenOffice Code Execution Vulnerability via Malicious Spreadsheets
Security researchers have demonstrated a proof-of-concept vulnerability in LibreOffice and Apache OpenOffice that allows malicious spreadsheets to execute arbitrary code upon opening, bypassing macro security warnings. The exploit relies on Java support being enabled within the office suite, posing a significant risk for silent code execution.
Overview
A critical vulnerability has been identified in LibreOffice and Apache OpenOffice, allowing for arbitrary code execution when a specially crafted spreadsheet is opened. This attack bypasses standard macro security warnings, presenting a significant risk to users with Java support enabled in their office suite. While currently a proof-of-concept, the potential for silent code execution makes this a high-severity concern.
Technical Analysis
The vulnerability enables an attacker to embed code within a spreadsheet that executes immediately upon file opening, without any user prompt or macro warning.
* Affected Software: LibreOffice, Apache OpenOffice.
* Attack Vector: Maliciously crafted spreadsheet file (e.g., ODS, XLSX) delivered via phishing or other means.
* Prerequisites: The target system’s LibreOffice or OpenOffice installation must have Java support enabled.
* Execution Flow: The exploit leverages the enabled Java support to run attacker-controlled code, bypassing typical security mechanisms designed to alert users about executable content.
* Current Status: Demonstrated as a proof-of-concept; no active exploitation reported at the time of writing.
Detection
Detecting this specific exploit would involve monitoring for unusual process creation or network activity originating from LibreOffice or OpenOffice processes.
* Process Monitoring: Look for soffice.bin (LibreOffice) or soffice.exe (OpenOffice) spawning unusual child processes like cmd.exe, powershell.exe, sh, java.exe, or other scripting interpreters.
* Network Connections: Monitor for outbound network connections initiated by LibreOffice/OpenOffice processes to suspicious external IP addresses or domains.
* File System Activity: Look for suspicious file writes or modifications in unusual directories by the office suite processes.
Sigma Detection Rules
LibreOffice OpenOffice Spawning Command Shell
title: LibreOffice OpenOffice Spawning Command Shell
id: 75239121-1234-4567-8901-234567890123
status: experimental
description: Detects LibreOffice or OpenOffice processes spawning command interpreters, which could indicate exploitation of the code execution vulnerability bypassing macro warnings.
logsource:
product: windows
service: sysmon
detection:
selection:
ParentImage|endswith:
- '\soffice.bin'
- '\soffice.exe'
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\bash.exe'
- '\sh.exe'
condition: selection
level: high
Mitigations
- Disable Java Support: If not strictly required for legitimate workflows, disable Java within LibreOffice/OpenOffice settings to remove the primary prerequisite for this exploit.
- User Awareness Training: Educate users about the risks of opening unsolicited or suspicious spreadsheet files, even if they appear to bypass security warnings.
- Endpoint Detection and Response (EDR): Deploy and configure EDR solutions to monitor for and block suspicious process creation and network activity originating from office applications.
- Email and Web Filtering: Implement robust email and web filtering to block known malicious files and prevent their delivery to end-users.
- Application Whitelisting: Consider application whitelisting to restrict which executables can be launched by office applications.
References
- https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
Generated by
gemini-2.5-flash ·1,545 input / 1,024 output tokens ·
Reviewed and approved by a human analyst before publication