ZeroHour

CVE-2021-26618

CVSS 3.1
9.8 critical
EPSS
<1%p61
Published
()
Modified
Description

An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code.

Vendors
tmax
Products
tooffice
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.