CVE-2025-1080: Macro URL arbitrary script execution
Published Mar 4, 2025
·Updated
Last updated 11 March 2025
Affected Software
6 affected componentsFixes available
The Document Foundation LibreOffice>=24.8, <24.8.5
The Document Foundation LibreOffice>=25.2, <25.2.1
debian/libreoffice<=1:7.0.4-4+deb11u10, <=1:7.0.4-4+deb11u12, <=4:7.4.7-1+deb12u5
4:7.4.7-1+deb12u74:25.2.1-3
LibreOffice Libreoffice>=24.8.0.0<24.8.5.1
LibreOffice Libreoffice>=25.2.0.0<25.2.1.1
Debian Debian Linux=11.0
Event History
Mar 4, 2025
CVE Published
via MITRE·08:04 PM
Data Sourced
via MITRE·08:04 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Data Sourced
via Red Hat·09:01 PM
DescriptionSeverityAffected Software
Mar 10, 2025
Data Sourced
via Launchpad·02:26 PM
Description
Mar 14, 2025
Data Sourced
via Ubuntu·02:26 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-1080?
CVE-2025-1080 is classified as a moderate severity vulnerability affecting specific versions of LibreOffice.
2
How do I fix CVE-2025-1080?
To fix CVE-2025-1080, users should update LibreOffice to the latest available version that addresses this vulnerability.
3
Which versions of LibreOffice are affected by CVE-2025-1080?
CVE-2025-1080 affects LibreOffice versions 24.8 to 24.8.5 and 25.2 to 25.2.1.
4
What specific feature in LibreOffice is related to CVE-2025-1080?
CVE-2025-1080 is related to the additional URI scheme 'vnd.libreoffice.command' that integrates LibreOffice with MS SharePoint.
5
What potential impact does CVE-2025-1080 have on users?
CVE-2025-1080 may allow an attacker to execute unintended commands via malicious links targeting affected versions of LibreOffice.