peter bassill · operator
$ cve CVE-2018-6871 JSON

CVE-2018-6871 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 22.8% (pctl 98)

Patch early

A public exploit exists.

Description

LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS22.8% — more likely to be exploited than 98% of all CVEs
On CISA KEVno
Public exploityes
Published2018-02-09
Last modified2026-06-17

Affected (9)

VendorProduct
canonicalubuntu linux
debiandebian linux
libreofficelibreoffice
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD