Description
Information disclosure vulnerabilities were found in LibreOffice. Malicious users can exploit these vulnerabilities to obtain sensitive information, gain privileges.
Original advisories
CVE-2024-12425: Path traversal leading to arbitrary .ttf file write
- CVE-2024-12426: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables
Exploitation
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Related products
CVE list
- CVE-2024-12425 warning
- CVE-2024-12426 high
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!