← back
CVE-2022-33896highobserved exploitationCWE-124

CVE-2022-33896

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 7.8epss 0.5%
from disclosure to weapon
Published on NVDOct 7
VulnCheck+1116d
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
yesVulnCheck
A buffer underflow vulnerability exists in the way Hword of Hancom Office 2020 version 11.0.0.5357 parses XML-based office files. A specially-crafted malformed file can cause memory corruption by using memory before buffer start, which can lead to code execution. A victim would need to access a malicious file to trigger this vulnerability.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H