<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:the_document_foundation:libreoffice:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3athe_document_foundationlibreoffice/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 09 Sep 2026 12:54:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3athe_document_foundationlibreoffice/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Creation Vulnerability in LibreOffice</title><link>https://feed.craftedsignal.io/briefs/2026-09-libreoffice-file-creation/</link><pubDate>Wed, 09 Sep 2026 12:54:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-libreoffice-file-creation/</guid><description>A vulnerability in LibreOffice (CVE-2024-7737) allows a remote attacker to create arbitrary files on a user's system by exploiting improper document feature handling.</description><content:encoded><![CDATA[<p>A vulnerability identified as CVE-2024-7737 exists in LibreOffice versions prior to 24.2.6. The flaw is caused by the improper handling of specific document features within the software, which may allow an unauthenticated remote attacker to create arbitrary files on a victim's local system when a maliciously crafted document is opened. This vulnerability poses a risk of unauthorized file system write operations. Users are advised to upgrade to the latest stable version of LibreOffice to mitigate this risk.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthorized file creation on the targeted host. Depending on the location and contents of the generated files, this could facilitate further malicious activities such as the overwriting of system configuration files, the placement of files in startup directories, or the creation of local execution artifacts. The vulnerability affects users on Windows, Linux, and macOS platforms.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all LibreOffice installations to version 24.2.6 or later to address the vulnerability documented in CVE-2024-7737.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category></item></channel></rss>