CVE-2023-2255 is an improper access-control vulnerability in The Document Foundation LibreOffice editor components. LibreOffice documents containing floating frames linked to external files could cause the linked content to load without requesting user permission. This behavior was inconsistent with the prompting applied to other linked content. Affected releases are LibreOffice 7.4 before 7.4.7 and 7.5 before 7.5.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python-based exploit for CVE-2023-2255, targeting office suites (such as LibreOffice or OpenOffice) that support embedded Python scripts in ODT files. The main script, 'exploit.py', takes a payload Python file (by default 'payload.py') and embeds its contents into a specially crafted 'content.xml' within a ZIP archive structured as an ODT file. The payload ('payload.py') is a Python script that, when executed on a Windows system, creates a new user 'hacker' with the password 'P@ssw0rd' and adds this user to the Administrators group, effectively granting full system access. The exploit requires the victim to open the malicious ODT file with a vulnerable application. The repository is structured with two main code files: 'exploit.py' (the exploit builder) and 'payload.py' (the embedded payload). No network endpoints are present; the attack vector is local execution via document opening.
This repository provides an exploit for CVE-2023-2255, a remote code execution vulnerability affecting software that processes ODT (OpenDocument Text) files. The main exploit script (CVE-2023-2255.py) takes a template ODT file, injects a user-supplied command payload, and repackages it as a new ODT file. When this malicious ODT file is processed by a vulnerable application, the embedded command is executed on the target system. The README demonstrates usage by showing how to craft a payload that downloads a PHP webshell (webshell.php) from a remote URL. The included webshell is a minimal PHP script that executes system commands provided via a GET parameter. The repository consists of the exploit script (Python), a sample webshell (PHP), and documentation. The exploit is operational and can be used to achieve arbitrary command execution on vulnerable systems.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.