Home

Description

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Hancom Inc. Hancom Office 2018, Hancom Inc. Hancom Office 2020, Hancom Inc. Hancom Office 2022, Hancom Inc. Hancom Office 2024 allows File Content Injection.This issue affects Hancom Office 2018: before 10.0.0.12681; Hancom Office 2020: before 11.0.0.8916; Hancom Office 2022: before 12.0.0.4426; Hancom Office 2024: before 13.0.0.3050.

PUBLISHED Reserved 2025-03-12 | Published 2026-02-04 | Updated 2026-02-04 | Assigner krcert




HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

Product status

Default status
unaffected

Any version before 10.0.0.12681
affected

Default status
unaffected

Any version before 11.0.0.8916
affected

Default status
unaffected

Any version before 12.0.0.4426
affected

Default status
unaffected

Any version before 13.0.0.3050
affected

References

www.boho.or.kr/...5023&pageIndex=1&categoryCode=&nttId=71959

www.hancom.com/support/downloadCenter/download

cve.org (CVE-2025-29867)

nvd.nist.gov (CVE-2025-29867)

Download JSON