PT-2017-8463 · Hancom · Hancom Office

Published

2017-01-06

·

Updated

2017-01-11

·

CVE-2016-4296

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hancom Office 2014
Description The issue occurs when opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object. The application searches for an underscore (" ") character at the end of the string and writes a null terminator after it. If the character is at the very end of the string, the application mistakenly writes the null-byte outside the bounds of its destination, resulting in heap corruption. This can lead to code execution under the context of the application.
Recommendations For Hancom Office 2014, avoid opening Hangul Hcell Documents (.cell) that may trigger the vulnerability until a patch is available. As a temporary workaround, consider restricting the use of the CSSValFormat object in Hangul Hcell Documents to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4296

Affected Products

Hancom Office