Proof-of-concept virus gives insight into OpenOffice.org security failings
A group of malware developers have produced a proof-of-concept virus that uses OpenOffice macros. The virus, which is embedded in a specially crafted OpenOffice Draw document, can execute scripts with user-level permissions …
Context & Ripple Effects
The corpus carries no earlier OpenOffice security reporting, so this proof-of-concept lands without an established beat behind it — which is itself the story's frame. Malware authors demonstrated that OpenOffice macros, embedded in a Draw document, execute scripts with user-level permissions, and the write-up was picked up same-day by APC ('First OpenOffice virus emerges') and by Sophos, which flagged the 'BadBunny' worm and openly questioned whether it had been seen outside the lab.
Why it matters on 2007-05-23: OpenOffice's cross-platform macro scripting had been pitched as a portability asset, and its smaller installed base fed an assumption that it sat below attackers' threshold of interest. A working, multi-platform macro sample from researchers tests both claims at once.
First-order effects
- OpenOffice.org maintainers face immediate pressure to tighten macro-security defaults and warning prompts, since the Draw vector shows user-level script execution is reachable from an ordinary-looking document.
- Antivirus vendors such as Sophos move to signature the 'BadBunny' sample, while its proof-of-concept status leaves unresolved whether any copy is actually circulating in the wild.
Second-order effects
- Enterprises evaluating OpenOffice deployments have to price macro policy into adoption decisions, weakening the 'fewer targets means safer' argument that had differentiated the suite from Microsoft Office.
- Rival office-suite makers inherit the question by extension: if macros work cross-platform here, every suite exposing a scripting layer in documents becomes a candidate vector, forcing each vendor to justify its own default protections.
Third-order effects
- If the pattern holds, office documents consolidate as an attack surface independent of vendor or market share — the format, not the popularity of the application, becomes the delivery mechanism.
- That points toward macro execution being treated industry-wide as a privilege boundary requiring explicit user consent and sandboxing, rather than a convenience feature enabled by default.
The trend: Office-suite malware is shifting from targeting the dominant vendor to exploiting shared macro-scripting features across platforms, making the document format itself the common attack surface.