Vulnerability record · CVE-2021-33035 · published 23 September 2021
CVE-2021-33035: Apache OpenOffice DBF field buffer overflow allows code execution
Apache · Openoffice
Apache OpenOffice fails to validate the size of certain fields when reading dBase/DBF documents, copying unchecked data into fixed local variables. A crafted DBF file overflows the stack, corrupting return data and enabling arbitrary code execution. The flaw affects OpenOffice up to and including 4.1.10 and matters because document files are a routine, trusted-looking delivery path.
Description
Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully crafted document could overflow the allocated space, leading to the execution of arbitrary code by altering the contents of the program stack. This issue affects Apache OpenOffice up to and including version 4.1.10
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with full code execution and high EPSS, though exploitation requires the victim to open a crafted file and no KEV listing exists.
What it is
Apache OpenOffice fails to validate the size of certain fields when reading dBase/DBF documents, copying unchecked data into fixed local variables. A crafted DBF file overflows the stack, corrupting return data and enabling arbitrary code execution. The flaw affects OpenOffice up to and including 4.1.10 and matters because document files are a routine, trusted-looking delivery path.
Impact
An attacker who gets a victim to open a malicious DBF document can execute arbitrary code in the context of the OpenOffice process, giving full control of confidentiality, integrity and availability on that host.
Attack surface
Reached locally by opening a crafted DBF document in Apache OpenOffice; the CVSS vector requires user interaction (UI:R) and no privileges (PR:N), so the victim must open the file. No network service is exposed by this flaw.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of attempted exploitation. References include patch commits and advisories but no public exploit tag.
What to do
- Upgrade Apache OpenOffice past 4.1.10 to a version containing the fix, or apply the referenced patch commit.
- If upgrade is not possible, block or restrict opening of untrusted DBF/dBase files in OpenOffice.
- Treat DBF attachments and downloads from external sources as untrusted; scan and quarantine before opening.
- Consider migrating users to a maintained office suite if OpenOffice cannot be kept patched.
Detection
- Monitor for OpenOffice processes spawning unexpected child processes such as cmd.exe, powershell.exe or /bin/sh.
- Alert on crashes or abnormal terminations of soffice processes when opening DBF files.
- Log and review file-open events for .dbf files originating from email attachments or downloads.
- Hunt for DBF files with anomalous field-length metadata or unusually large field values.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-33035 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-33035), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.