hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text tag.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HHancom Hangul Word Processor
APPHancom2014
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References
Related vulnerabilities
CVE-2017-2819HIGH8.8same product
An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) o...
CVE-2018-5195CRITICAL9.8PL ✓same vendor
Buffer overflow w Hancom NEO umożliwiający zdalne wykonanie kodu
CVE-2023-50234HIGH7.8same vendor
Hancom Office Cell XLS File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...
CVE-2023-50235HIGH7.8same vendor
Hancom Office Show PPT File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...
CVE-2023-51598HIGH8.8same vendor
Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability all...