Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-33896

Опубликовано: 07 окт. 2022
Источник: nvd
CVSS3: 7.8
CVSS3: 7.8
EPSS Низкий

Описание

A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hancom:hancom_office_2020:11.0.0.5357:*:*:*:*:*:*:*

EPSS

Процентиль: 52%
0.00293
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-124

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.

EPSS

Процентиль: 52%
0.00293
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-124