HIGH🇵🇱 Wersja polska

CVE-2023-51598

CVSS 8.8v3.1pub. 2024-05-03upd. 2025-08-14

Hancom Office Word DOC File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hancom Office Word. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DOC files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-20384.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Hancom Office Word

    APP
    Hancom
    11.0.0.6914
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2018-5195CRITICAL9.8PL ✓same vendor

Buffer overflow w Hancom NEO umożliwiający zdalne wykonanie kodu

CVE-2023-50234HIGH7.8same vendor

Hancom Office Cell XLS File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...

CVE-2023-50235HIGH7.8same vendor

Hancom Office Show PPT File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vuln...

CVE-2023-40250HIGH8.8same vendor

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Window...

CVE-2023-32541HIGH8.8same vendor

A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A ...