LibreOffice documents can contain macros. The execution of those macros is controlled by the document security settings, typically execution of macros are blocked by default. A URL decoding flaw existed in how the urls to the macros within the document were processed and categorized, resulting in the possibility to construct a document where macro execution bypassed the security settings. The documents were correctly detected as containing macros, and prompted the user to their existence within the documents, but macros within the document were subsequently not controlled by the security settings allowing arbitrary macro execution This issue affects: LibreOffice 6.2 series versions prior to 6.2.7; LibreOffice 6.3 series versions prior to 6.3.1.
総合評価: CVE-2019-9853 は中リスク(64.4/100)。CVSS 深刻度は高。悪用される可能性が高い(EPSS 3.21%、87 パーセンタイル) 根拠: 直近 1 日で EPSS が +2.92% 上昇。悪用への関心が高まっている可能性があります。 推奨対応: 影響資産を整理し、修補計画に組み込んでください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.29% | 3.21% | +2.92% |
| 2 | 2025-11-21 | 0.69% | 0.29% | -0.40% |
| 3 | 2025-11-18 | — | 0.69% | — |
EPSS の全履歴 (全 18 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2019-9853: 1 source package rows (libreoffice); 4 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 4. | https://security.alpinelinux.org/vuln/CVE-2019-9853 |
debian
|
not yet assigned | CVE-2019-9853 not yet assigned priority: Debian including 1 source packages (libreoffice), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-9853 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2019-9853 |
suse
|
medium | CVE-2019-9853 severity moderate: SUSE including 1483 source package names (bluez-5.13-5.20.6, bluez-cups-5.13-5.20.6, …), 3223 product×package rows across 41 product lines (SUSE Linux Enterprise Module for Basesystem 15, SUSE Linux Enterprise Module for Basesystem 15 SP1, … (41 product lines)): Fixed 2970, Known Not Affected 253. | https://www.suse.com/security/cve/CVE-2019-9853/ |
ubuntu
|
medium | CVE-2019-9853 medium priority: Ubuntu including 1 source packages (libreoffice), 5 status rows across 5 suites (bionic, disco, trusty, upstream, xenial): released 4, DNE 1. | https://ubuntu.com/security/CVE-2019-9853 |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| libreoffice | libreoffice | >= 6.2.0, < 6.2.6 | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
| libreoffice | libreoffice | >= 6.3.0, < 6.3.1 | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |