$ techbeacon▋
CVE & Exploits

Security Flaw Lets Malicious Spreadsheets Execute Code in LibreOffice and OpenOffice Without Macro Alerts

Security Flaw Lets Malicious Spreadsheets Execute Code in LibreOffice and OpenOffice Without Macro Alerts

Security researchers have uncovered a vulnerability that enables a specially crafted spreadsheet to run attacker‑controlled code the moment it is opened in LibreOffice or Apache OpenOffice, bypassing the macro warnings these suites normally display.

The issue stems from how the programs process certain spreadsheet elements that can trigger code execution without being classified as a macro. Because the payload is hidden inside ordinary data structures, the built‑in macro‑warning dialog never appears, allowing the malicious payload to run silently. The exploit is effective only when the application’s default automatic‑evaluation features are active, a setting that is enabled in typical installations.

LibreOffice and OpenOffice are among the most popular open‑source office suites, serving millions of users on Linux desktops, in government agencies, and in educational institutions. Macro warnings have long been a frontline defense against malicious documents, mirroring similar safeguards in Microsoft Office. The new flaw undermines that protection, raising concerns for any user who opens spreadsheets from untrusted sources.

According to the researchers who disclosed the problem, the vulnerability has been reported to the maintainers of both projects, and patches are already in development. They recommend that users refrain from opening unknown spreadsheet files until the fix is released, and consider disabling automatic formula evaluation as a temporary mitigation. The forthcoming updates are expected to add stricter validation of embedded content and restore the macro warning for the affected code paths.

The discovery highlights ongoing challenges in securing open‑source software, where rapid development cycles can sometimes outpace thorough security testing. It also serves as a reminder that users must stay current with software updates and apply cautious handling of documents from unfamiliar origins. As the patches roll out, both LibreOffice and OpenOffice communities are expected to reinforce their security review processes to prevent similar bypasses in the future.

Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related