HIGHvulnerability·

LibreOffice and OpenOffice Code Execution Vulnerability via Malicious Spreadsheets

Security researchers have demonstrated a proof-of-concept vulnerability in LibreOffice and Apache OpenOffice that allows malicious spreadsheets to execute arbitrary code upon opening, bypassing macro security warnings. The exploit relies on Java support being enabled within the office suite, posing a significant risk for silent code execution.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

A critical vulnerability has been identified in LibreOffice and Apache OpenOffice, allowing for arbitrary code execution when a specially crafted spreadsheet is opened. This attack bypasses standard macro security warnings, presenting a significant risk to users with Java support enabled in their office suite. While currently a proof-of-concept, the potential for silent code execution makes this a high-severity concern.

Technical Analysis

The vulnerability enables an attacker to embed code within a spreadsheet that executes immediately upon file opening, without any user prompt or macro warning.
* Affected Software: LibreOffice, Apache OpenOffice.
* Attack Vector: Maliciously crafted spreadsheet file (e.g., ODS, XLSX) delivered via phishing or other means.
* Prerequisites: The target system’s LibreOffice or OpenOffice installation must have Java support enabled.
* Execution Flow: The exploit leverages the enabled Java support to run attacker-controlled code, bypassing typical security mechanisms designed to alert users about executable content.
* Current Status: Demonstrated as a proof-of-concept; no active exploitation reported at the time of writing.

Detection

Detecting this specific exploit would involve monitoring for unusual process creation or network activity originating from LibreOffice or OpenOffice processes.
* Process Monitoring: Look for soffice.bin (LibreOffice) or soffice.exe (OpenOffice) spawning unusual child processes like cmd.exe, powershell.exe, sh, java.exe, or other scripting interpreters.
* Network Connections: Monitor for outbound network connections initiated by LibreOffice/OpenOffice processes to suspicious external IP addresses or domains.
* File System Activity: Look for suspicious file writes or modifications in unusual directories by the office suite processes.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

LibreOffice OpenOffice Spawning Command Shell

title: LibreOffice OpenOffice Spawning Command Shell
id: 75239121-1234-4567-8901-234567890123
status: experimental
description: Detects LibreOffice or OpenOffice processes spawning command interpreters, which could indicate exploitation of the code execution vulnerability bypassing macro warnings.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    ParentImage|endswith:
      - '\soffice.bin'
      - '\soffice.exe'
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\bash.exe'
      - '\sh.exe'
  condition: selection
level: high

Mitigations

  1. Disable Java Support: If not strictly required for legitimate workflows, disable Java within LibreOffice/OpenOffice settings to remove the primary prerequisite for this exploit.
  2. User Awareness Training: Educate users about the risks of opening unsolicited or suspicious spreadsheet files, even if they appear to bypass security warnings.
  3. Endpoint Detection and Response (EDR): Deploy and configure EDR solutions to monitor for and block suspicious process creation and network activity originating from office applications.
  4. Email and Web Filtering: Implement robust email and web filtering to block known malicious files and prevent their delivery to end-users.
  5. Application Whitelisting: Consider application whitelisting to restrict which executables can be launched by office applications.

References

  • https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,545 input / 1,024 output tokens ·
Reviewed and approved by a human analyst before publication
#vulnerability#code-execution#high#java#libreoffice#openoffice#spreadsheet#vulnerability