PT-2026-5240 · Hancom · Hancom Office
Published
2026-01-28
·
Updated
2026-02-04
·
CVE-2025-29867
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Hancom Office 2018 versions prior to 10.0.0.12681
Hancom Office 2020 versions prior to 11.0.0.8916
Hancom Office 2022 versions prior to 12.0.0.4426
Hancom Office 2024 versions prior to 13.0.0.3050
Description
An Access of Resource Using Incompatible Type ('Type Confusion') issue exists in Hancom Office 2018, Hancom Office 2020, Hancom Office 2022, and Hancom Office 2024. This issue allows for File Content Injection. A 'Type Confusion' occurs when a program attempts to access a resource using an incorrect data type, potentially leading to unexpected behavior or security compromises.
Recommendations
Hancom Office 2018 versions prior to 10.0.0.12681 should be updated to version 10.0.0.12681 or later.
Hancom Office 2020 versions prior to 11.0.0.8916 should be updated to version 11.0.0.8916 or later.
Hancom Office 2022 versions prior to 12.0.0.4426 should be updated to version 12.0.0.4426 or later.
Hancom Office 2024 versions prior to 13.0.0.3050 should be updated to version 13.0.0.3050 or later.
Fix
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hancom Office