← Vulnerability feed

Vulnerability record · CVE-2025-64401 · published 12 November 2025

CVE-2025-64401: Apache openoffice missing authorization vulnerability

Apache · Openoffice

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "floating frames" linked to external files would load the contents of those frames without prompting the user for permission to do so. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue. The LibreOffice suite reported this issue as CVE-2023-2255

7.5 CVSS 3.1 High EPSS 0.86% · top 43.1% CWE-862 · Missing authorization
7.5CVSS 3.1 base score
0.86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, documents that used "floating frames" linked to external files would load the contents of those frames without prompting the user for permission to do so. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue. The LibreOffice suite reported this issue as CVE-2023-2255

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-64401 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2014-3524Apache openoffice command injection vulnerabilityApache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc sp…EPSS 15%9.3CVE-2010-3450Apache openoffice path traversal vulnerabilityMultiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a…EPSS 11%9.3CVE-2010-3451Apache openoffice use after free vulnerabilityUse-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…EPSS 10%9.3CVE-2010-3452Apache openoffice use after free vulnerabilityUse-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applica…EPSS 10%9.3CVE-2010-3453Apache openoffice out-of-bounds write vulnerabilityThe WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number…EPSS 9.7%9.3CVE-2010-3454Apache openoffice vulnerabilityMultiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote atta…EPSS 10%9.3CVE-2010-4253Apache openoffice out-of-bounds write vulnerabilityHeap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…EPSS 10%9.3CVE-2010-4643Apache openoffice out-of-bounds write vulnerabilityHeap-based buffer overflow in Impress in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (applicatio…EPSS 10%

Source: NIST National Vulnerability Database (record CVE-2025-64401), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.