CVE-2016-4293: Hancom Office 2014

High severity, CVSS 7.8. EPSS: 3.6% chance of exploitation in the next 30 days.

Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2014 VP allow remote attackers to execute arbitrary code via a crafted Hangul Hcell Document (.cell) file.

Affected products

  • Hancom Hancom Office 2014: version 9.1.0.2176 only

Published 2017-04-20. Last modified 2026-06-17.