Showing 2 vulnerabilities on this page for hancom_office_2020

Signals CISA KEV Ransomware Nuclei
Hancom vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially crafted .doc file can lead to a use-after-free. An attacker can trick a user into opening a malformed file to trigger this vulnerability.

CWE-416Sep 26, 2023
CVSS8.8v3.1EPSS0.655%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

hancom hancom_office_2020 Buffer Underwrite ('Buffer Underflow')

A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.

CWE-124Oct 7, 2022
CVSS7.8v3.1EPSS0.516%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX