CVE-2022-26305


Execution of Untrusted Macros Due to Improper Certificate Validation

An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually signed with the certificate. An adversary could therefore create an arbitrary certificate with a serial number and an issuer string identical to a trusted certificate which LibreOffice would present as belonging to the trusted author, potentially leading to the user to execute arbitrary code contained in macros improperly trusted. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.



We have discovered 108 live websites that are affected by CVE-2022-26305.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 7.2 before 7.2.7
  • from 7.3 before 7.3.1
Total Vulnerable Versions195
Vulnerable Domains108 live websites (3.20% of LibreOffice install base)


Common Weakness Enumeration


CWE-295 Improper Certificate Validation



Details

  • Published - Jul 25, 2022
  • Updated - Mar 26, 2023

Credits

  • OpenSource Security GmbH on behalf of the German Federal Office for Information Security





Countries

United States19 websites



Germany35 websites
France12 websites
GB7 websites
Argentina3 websites
China3 websites
Hungary3 websites
Russia3 websites
Austria2 websites

TLDs

.de24 websites
.com23 websites
.org9 websites
.fr8 websites
.co.uk5 websites
.net5 websites
.ru3 websites
.at2 websites
.nl2 websites
.cn2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2022-26305

Top websites that are affected by CVE-2022-26305. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.***.cn China*,***,***
************.de Germany*,***,***
******.*********.de Germany*,***,***
***********.com *,***,***
****************************.de Germany*,***,***
***.*******.com United States*,***,***
***.***.cn China*,***,***
****.org United States*,***,***
****************.de Germany*,***,***
**************.net Germany*,***,***
See full domain list