CVE-2025-2866

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 27, 2025
Updated: May 12, 2025
CWE ID 347

Summary

CVE-2025-2866 is a vulnerability affecting LibreOffice, where improper verification of cryptographic signatures in adbe.pkcs7.sha1 signatures may lead to signature spoofing. LibreOffice versions 24.8 before 24.8.6 and 25.2 before 25.2.2 are impacted. The flaw in the verification code allows for the acceptance of invalid signatures, posing a risk to document authenticity. Exploitation of this vulnerability could result in unauthorized modification of PDF files. Users are strongly advised to update their LibreOffice installations to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • LibreOffice

Affected Vendors

  • Libre Office