1 results (0.010 seconds)

CVSS: 7.8EPSS: 2%CPEs: 1EXPL: 0

hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text tag. La biblioteca hwpapp.dll en Hangul Word Processor permite a los atacantes remotos ejecutar código arbitrario por medio de un heap spray creado, y al aprovechar una "type confusion" por medio de un archivo HWPX que contiene una etiqueta de texto para creada. • http://www.hancom.com/cs_center/csDownload.do http://www.securityfocus.com/bid/76694 https://www.fireeye.com/blog/threat-research/2015/09/zero-day_hwp_exploit.html https://www.fireeye.com/content/dam/fireeye-www/global/en/blog/threat-research/FireEye_HWP_ZeroDay.pdf • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •