A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory corruption and potential arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
References
Link | Resource |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1386 | Exploit Third Party Advisory |
https://blog.talosintelligence.com/2022/02/vuln-spotlight-.html | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-02-16 09:15
Updated : 2022-05-12 13:03
NVD link : CVE-2021-21958
Mitre link : CVE-2021-21958
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
hancom
- hancom_office_2020