vendor:
LibreOffice
by:
Richard Davy
N/A
CVSS
N/A
Malicious ODF file creation
CWE
Product Name: LibreOffice
Affected Version From: LibreOffice 6.0.3, OpenOffice 4.1.5
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10
2018
Malicious ODF File Creator
This script creates a malicious ODF file that can be used to leak NetNTLM credentials. It works against LibreOffice 6.0.3 and OpenOffice 4.1.5. The script creates a blank ODT file and then modifies the content.xml file to include the payload.
Mitigation:
Ensure that the software is up to date and does not allow the execution of malicious ODF files.