CVE-2016-4293 describes multiple heap-based buffer overflows in Hancom Office 2014 VP, specifically within the CBookBase::SetDefTableStyle and CBookBase::SetDefPivotStyle functions. This vulnerability allows remote attackers to execute arbitrary code by tricking a user into opening a specially crafted Hangul Hcell Document (.cell) file. With a CVSS score of 7.8 (High), successful exploitation could lead to high confidentiality, integrity, and availability impacts, though it requires user interaction. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.1.0.2176CPE matchmatch criteria | cpe:2.3:a:hancom:hancom_office_2014:9.1.0.2176:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.