CVE-2014-3524

critical
Published 2014-08-26 · Modified 2026-05-06
CVSS v3
CVSS v2
9.3
VIR risk
9.3

Description

Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openoffice.org/security/cves/CVE-2014-3524.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://blog.documentfoundation.org/2014/08/28/libreoffice-4-3-1-fresh-announced/

Application impact

VendorProductVersionsFixed
apache apacheopenoffice{"endExcluding":"4.1.1"}4.1.1
libreofficelibreoffice{"endExcluding":"4.2.6"}4.2.6

References

CWEs

CWE-77

Verify integrity in audit chain (admin only). AS-IS.