Vulnerability record · CVE-2025-64405 · published 12 November 2025
CVE-2025-64405: Apache openoffice missing authorization vulnerability
Apache · Openoffice
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, Calc spreadsheet containing DDE links to external files would load the contents of those files without prompting the user for permission to do so. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.
Description
Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of Apache OpenOffice, Calc spreadsheet containing DDE links to external files would load the contents of those files without prompting the user for permission to do so. This issue affects Apache OpenOffice: through 4.1.15. Users are recommended to upgrade to version 4.1.16, which fixes the issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.apache.org/thread/0jjftxkcc4l9kt7jjn630hfrh2ygfcbk | Mailing ListVendor Advisory |
| https://www.openoffice.org/security/cves/CVE-2025-64405.html | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/11/11/8 | Mailing ListThird Party Advisory |
Track CVE-2025-64405 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-64405), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.