Lucene search

K
cve[email protected]CVE-2022-33896
HistoryOct 07, 2022 - 3:15 p.m.

CVE-2022-33896

2022-10-0715:15:15
CWE-124
web.nvd.nist.gov
26
4
cve-2022-33896
buffer underflow
hancom office
code execution
xml
vulnerability
nvd

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

36.5%

A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.

Affected configurations

Vulners
NVD
Node
hancomhancom_office_2020RangeHancom Office 2020 11.0.0.5357
VendorProductVersionCPE
hancomhancom_office_2020*cpe:2.3:a:hancom:hancom_office_2020:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Hancom",
    "product": "Hancom Office 2020",
    "versions": [
      {
        "version": "Hancom Office 2020 11.0.0.5357",
        "status": "affected"
      }
    ]
  }
]

Social References

More

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

36.5%

Related for CVE-2022-33896