#VU118358 Missing Authorization in OpenOffice - CVE-2025-64404

 

#VU118358 Missing Authorization in OpenOffice - CVE-2025-64404

Published: November 12, 2025


Vulnerability identifier: #VU118358
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2025-64404
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
OpenOffice
Software vendor:
Apache Foundation

Description

The vulnerability allows a remote attacker to perform spoofing attacks.

The vulnerability exists due to missing authorization checks when loading external content. A remote attacker can trick the victim into opening a specially crafted document with background fill images, or bullet images, linked to external files and load the content of those frames without prompting the user. 


Remediation

Install updates from vendor's website.

External links