← back
CVE-2021-41831

Timestamp Manipulation with Signature Wrapping

EPSS 1.5%CWE-347
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Oct 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25634 for the LibreOffice advisory.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →