A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code
as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.
The attack works only when the program's Java support is enabled. So far, it has only been shown as a proof of concept, and there are no reports of its use in real attacks.
Malicious spreadsheets can make LibreOffice and OpenOffice run Java code with Java enabled; LibreOffice has fixed the flaw.
thehackernews.com