Korean
<< Back
VID 50253
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The version of Hancom Office NEO installed on the remote host is a version 9.6.1.5183 and earlier. It has a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these conditions will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
https://boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=26983

* Platforms Affected:
Hancom Office NEO versions 9.6.1.5183 and earlier.
Microsoft Windows Any version
Recommendation Update to the latest version according to the information provided on the website.
https://www.hancom.com/cs_center/csDownload.do
Related URL CVE-2018-5195 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)