CVE-2025-29867 PUBLISHED

Assigner: krcert
Reserved: 12.03.2025 Published: 04.02.2026 Updated: 04.02.2026

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Hancom Inc. Hancom Office 2018, Hancom Inc. Hancom Office 2020, Hancom Inc. Hancom Office 2022, Hancom Inc. Hancom Office 2024 allows File Content Injection.This issue affects Hancom Office 2018: before 10.0.0.12681; Hancom Office 2020: before 11.0.0.8916; Hancom Office 2022: before 12.0.0.4426; Hancom Office 2024: before 13.0.0.3050.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Hancom Inc.
Product Hancom Office 2018
Versions Default: unaffected
  • affected from 0 to 10.0.0.12681 (excl.)
Vendor Hancom Inc.
Product Hancom Office 2020
Versions Default: unaffected
  • affected from 0 to 11.0.0.8916 (excl.)
Vendor Hancom Inc.
Product Hancom Office 2022
Versions Default: unaffected
  • affected from 0 to 12.0.0.4426 (excl.)
Vendor Hancom Inc.
Product Hancom Office 2024
Versions Default: unaffected
  • affected from 0 to 13.0.0.3050 (excl.)

References

Problem Types

  • CWE-843 Access of Resource Using Incompatible Type ('Type Confusion') CWE

Impacts

  • CAPEC-23 File Content Injection