VID |
50254 |
Severity |
30 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The version of Hancom Office 2010 installed on the remote host is a version 8.5.8.1724 and earlier. It has a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions. * Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these conditions will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30116
* Platforms Affected: Hancom Office 2010 versions 8.5.8.1724 and earlier. Microsoft Windows Any version |
Recommendation |
Update to the latest version according to the information provided on the website. https://www.hancom.com/cs_center/csDownload.do |
Related URL |
CVE-2018-5201 (CVE) |
Related URL |
(SecurityFocus) |
Related URL |
(ISS) |
|