{"id":"CVE-2021-25832","details":"A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.","modified":"2026-08-07T15:15:19.458411Z","published":"2021-03-01T16:15:14.433Z","references":[{"type":"ADVISORY","url":"https://github.com/ONLYOFFICE/core/blob/v6.0.1.15/ASCOfficePPTXFile/Editor/BinaryFileReaderWriter.cpp#L424"},{"type":"ADVISORY","url":"https://github.com/ONLYOFFICE/core/blob/v6.0.1.15/ASCOfficePPTXFile/Editor/BinaryFileReaderWriter.cpp#L428"},{"type":"ADVISORY","url":"https://github.com/ONLYOFFICE/core/blob/v6.0.1.15/DesktopEditor/cximage/CxImage/ximabmp.cpp#L354"},{"type":"ADVISORY","url":"https://github.com/ONLYOFFICE/core/blob/v6.0.1.15/DesktopEditor/cximage/CxImage/ximabmp.cpp#L358"},{"type":"PACKAGE","url":"https://github.com/ONLYOFFICE/DocumentServer"},{"type":"PACKAGE","url":"https://github.com/ONLYOFFICE/core"},{"type":"EVIDENCE","url":"https://github.com/merrychap/poc_exploits/tree/master/ONLYOFFICE/CVE-2021-25832"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/onlyoffice/documentserver","events":[{"introduced":"1e2a61f6f4321e2571474068595dfe23a657cbdf"},{"last_affected":"adaf61fd7747896a13891142b9c131568f71825f"}],"database_specific":{"cpe":"cpe:2.3:a:onlyoffice:document_server:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.0.0-9"},{"last_affected":"6.0.0"}],"source":"CPE_RANGE"}}],"versions":["ONLYOFFICE-DocumentServer-6.0.0","ONLYOFFICE-DocumentServer-5.6.5","ONLYOFFICE-DocumentServer-5.6.4","ONLYOFFICE-DocumentServer-5.6.3","ONLYOFFICE-DocumentServer-5.6.2","ONLYOFFICE-DocumentServer-5.6.1","ONLYOFFICE-DocumentServer-5.6.0","ONLYOFFICE-DocumentServer-5.5.3","ONLYOFFICE-DocumentServer-5.5.1","ONLYOFFICE-DocumentServer-5.5.0","ONLYOFFICE-DocumentServer-5.4.2","ONLYOFFICE-DocumentServer-5.4.1","ONLYOFFICE-DocumentServer-5.4.0-2","ONLYOFFICE-DocumentServer-5.3.4","ONLYOFFICE-DocumentServer-5.3.2","ONLYOFFICE-DocumentServer-5.3.1","ONLYOFFICE-DocumentServer-5.3.0","ONLYOFFICE-DocumentServer-5.2.8","ONLYOFFICE-DocumentServer-5.2.7","ONLYOFFICE-DocumentServer-5.2.6","ONLYOFFICE-DocumentServer-5.2.4","ONLYOFFICE-DocumentServer-5.2.3","ONLYOFFICE-DocumentServer-5.2.2","ONLYOFFICE-DocumentServer-5.2.0","ONLYOFFICE-DocumentServer-5.1.5","ONLYOFFICE-DocumentServer-5.1.4","ONLYOFFICE-DocumentServer-5.1.3","ONLYOFFICE-DocumentServer-5.1.2","ONLYOFFICE-DocumentServer-5.1.1","ONLYOFFICE-DocumentServer-5.1.0","ONLYOFFICE-DocumentServer-5.0.7","ONLYOFFICE-DocumentServer-5.0.6","ONLYOFFICE-DocumentServer-5.0.5","ONLYOFFICE-DocumentServer-5.0.4","ONLYOFFICE-DocumentServer-5.0.3","ONLYOFFICE-DocumentServer-4.4.3","ONLYOFFICE-DocumentServer-4.4.2","ONLYOFFICE-DocumentServer-4.4.1","ONLYOFFICE-DocumentServer-4.3.6","ONLYOFFICE-DocumentServer-4.3.5","ONLYOFFICE-DocumentServer-4.3.4","ONLYOFFICE-DocumentServer-4.3.3","ONLYOFFICE-DocumentServer-4.3.2","ONLYOFFICE-DocumentServer-4.3.1","ONLYOFFICE-DocumentServer-4.3.0","ONLYOFFICE-DocumentServer-4.2.11","ONLYOFFICE-DocumentServer-4.2.10","ONLYOFFICE-DocumentServer-4.2.9","ONLYOFFICE-DocumentServer-4.0.0-9","ONLYOFFICE-DocumentServer-4.2.8","ONLYOFFICE-DocumentServer-4.2.7","ONLYOFFICE-DocumentServer-4.2.5","ONLYOFFICE-DocumentServer-4.2.4","ONLYOFFICE-DocumentServer-4.2.3","ONLYOFFICE-DocumentServer-4.2.1","ONLYOFFICE-DocumentServer-4.2.0","ONLYOFFICE-DocumentServer-4.1.8-1","ONLYOFFICE-DocumentServer-4.1.6-3","ONLYOFFICE-DocumentServer-4.1.5-1","ONLYOFFICE-DocumentServer-4.1.4-3","ONLYOFFICE-DocumentServer-4.1.2-37","ONLYOFFICE-DocumentServer-4.0.3-3","ONLYOFFICE-DocumentServer-4.0.2-4","ONLYOFFICE-DocumentServer-4.0.1-34"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25832.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}