cve/2022/CVE-2022-33896.md
2024-06-18 02:51:15 +02:00

961 B

CVE-2022-33896

Description

A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.

POC

Reference

Github