CVE-2015-6585: Hancom Hangul Word Processor

High severity, CVSS 7.8. EPSS: 2.5% chance of exploitation in the next 30 days.

hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text tag.

Affected products

  • Hancom Hangul Word Processor: version 2014 only

Published 2017-07-25. Last modified 2026-06-17.