CVE-2025-2866
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 27, 2025
Updated: May 12, 2025
CWE ID 347
Summary
CVE-2025-2866 is a vulnerability affecting LibreOffice, where improper verification of cryptographic signatures in adbe.pkcs7.sha1 signatures may lead to signature spoofing. LibreOffice versions 24.8 before 24.8.6 and 25.2 before 25.2.2 are impacted. The flaw in the verification code allows for the acceptance of invalid signatures, posing a risk to document authenticity. Exploitation of this vulnerability could result in unauthorized modification of PDF files. Users are strongly advised to update their LibreOffice installations to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- LibreOffice
Affected Vendors
- Libre Office