CVE-2023-6186

Publication date 11 December 2023

Last updated 26 August 2025


Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

Description

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

Status

Package Ubuntu Release Status
libreoffice 23.10 mantic
Fixed 4:7.6.4-0ubuntu0.23.10.1
23.04 lunar
Fixed 4:7.5.9-0ubuntu0.23.04.1
22.04 LTS jammy
Fixed 1:7.3.7-0ubuntu0.22.04.4
20.04 LTS focal
Fixed 1:6.4.7-0ubuntu0.20.04.9
18.04 LTS bionic Ignored end of standard support
16.04 LTS xenial Ignored end of standard support
14.04 LTS trusty Ignored end of standard support

Severity score breakdown

CVSS version: CVSS v3.0

Base score 8.8 · High

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Related Ubuntu Security Notices (USN)

    • USN-6546-1
    • LibreOffice vulnerabilities
    • 11 December 2023
    • USN-6546-2
    • LibreOffice vulnerabilities
    • 14 December 2023

Other references


Access our resources on patching vulnerabilities