---
title: "CVE-2024-6472\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2024-6472?format=md
keywords: index, follow
---

# CVE-2024-6472

Publication date 5 August 2024

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2024-6472?format=md#impact-score)

Toggle side navigation

## Description

Certificate Validation user interface in LibreOffice allows potential
vulnerability.
Signed macros are scripts that have been digitally signed by the
developer using a cryptographic signature. When a document with a signed
macro is opened a warning is displayed by LibreOffice before the macro
is executed.
Previously if verification failed the user could fail to understand the
failure and choose to enable the macros anyway.
This issue affects LibreOffice: from 24.2 before 24.2.5.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libreoffice | 24.04 LTS noble | Fixed 4:24.2.5-0ubuntu0.24.04.2 |
| 22.04 LTS jammy | Fixed 1:7.3.7-0ubuntu0.22.04.6 |
| 20.04 LTS focal | Fixed 1:6.4.7-0ubuntu0.20.04.11 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6472)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2024-6472)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2024-6472)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2024-6472)

### Related Ubuntu Security Notices (USN)

+ [USN-6962-1](https://usn.ubuntu.com/USN-6962-1)
+ LibreOffice vulnerability
+ 15 August 2024

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2024-6472>
* <https://www.libreoffice.org/about-us/security/advisories/CVE-2024-6472>
