An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers use this vulnerability to execute arbitrary file included malicious code.Referenceshttps://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36456