Hancom Office 2020 vulnerabilities
3 known vulnerabilities affecting hancom/hancom_office_2020.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH3
Vulnerabilities
Page 1 of 1
CVE-2022-33896P2HIGHCVSS 7.8Exploitedv11.0.0.5357vHancom Office 2020 11.0.0.53572022-10-07
CVE-2022-33896 [HIGH] CWE-124 CVE-2022-33896: A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 p
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.
nvd
CVE-2023-32541P3HIGHCVSS 7.8v11.0.0.7520vHWord 11.0.0.75202023-09-27
CVE-2023-32541 [HIGH] CWE-416 CVE-2023-32541: A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.
A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially crafted .doc file can lead to a use-after-free. An attacker can trick a user into opening a malformed file to trigger this vulnerability.
nvd
CVE-2021-21958P3HIGHCVSS 7.8v11.0.0.2353vHancom Office 2020 11.0.0.23532022-02-16
CVE-2021-21958 [HIGH] CWE-122 CVE-2021-21958: A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom
A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory corruption and potential arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd