cbcvebase.
CVE-2018-6871
published 2018-02-09

CVE-2018-6871: LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the…

PriorityP267critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EXPLOIT
EPSS
23.20%
97.5th percentile
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibreoffice< libreoffice 1:6.0.1-1 (bookworm)libreoffice 1:6.0.1-1 (bookworm)
libreofficelibreoffice< 5.4.55.4.5
libreofficelibreoffice
libreofficelibreoffice>= 0 < 1:6.0.1-11:6.0.1-1
libreofficelibreoffice>= 0 < 1:6.0.1-11:6.0.1-1
libreofficelibreoffice>= 0 < 1:6.0.1-11:6.0.1-1
libreofficelibreoffice>= 0 < 1:6.0.1-11:6.0.1-1
libreofficelibreoffice>= 0 < 1:4.2.8-0ubuntu5.31:4.2.8-0ubuntu5.3
libreofficelibreoffice>= 0 < 1:5.1.6~rc2-0ubuntu1~xenial31:5.1.6~rc2-0ubuntu1~xenial3
redhatenterprise_linux_desktop
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation

Detection & IOCsextracted from sources · hover to see the quote

command=WEBSERVICE()
commandCOM.MICROSOFT.WEBSERVICE
  • Detect LibreOffice documents (ODS files) containing WEBSERVICE or COM.MICROSOFT.WEBSERVICE formula calls, which can be used to exfiltrate arbitrary local files to a remote attacker-controlled server.
  • Monitor outbound HTTP requests originating from LibreOffice processes (e.g., soffice, soffice.bin) to unexpected external hosts, which may indicate WEBSERVICE formula exfiltration in progress.
  • Inspect ODS/ODF spreadsheet XML content for the string 'WEBSERVICE' or 'COM.MICROSOFT.WEBSERVICE' in formula cells as a static file-based detection method.
  • ·Red Hat Enterprise Linux 8 ships a version of LibreOffice that is not affected by this CVE; detections targeting RHEL 8 endpoints may produce false positives if not version-gated.
  • ·The USN-3579-1 patch introduced a regression preventing LibreOffice from opening documents from certain locations outside the user's home directory; USN-3579-3 corrects this. Ensure the regression-fix update is applied alongside the security fix.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.