Missing Authorization in OpenOffice - CVE-2025-64404

 

Missing Authorization in OpenOffice - CVE-2025-64404

Published: November 12, 2025


Vulnerability identifier: #VU118358
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-64404
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attacks.

The vulnerability exists due to missing authorization checks when loading external content. A remote attacker can trick the victim into opening a specially crafted document with background fill images, or bullet images, linked to external files and load the content of those frames without prompting the user. 


Affected software

OpenOffice

How to mitigate CVE-2025-64404

Install updates from vendor's website.

OpenOffice - update to 4.1.16

External References

Related Security Bulletins