CVE-2024-7262 - Kingsoft WPS Office Path Traversal Vulnerability
Project:Kingsoft
Product:WPS Office
Date Added:2024-09-03Due Date:2024-09-24
Vulnerability Name
Kingsoft WPS Office Path Traversal Vulnerability
Description
Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
While CISA cannot confirm the effectiveness of patches at this time, it is recommended that mitigations be applied per vendor instructions if available. If these instructions cannot be located or if mitigations are unavailable, discontinue the use of the product.
https://nvd.nist.gov/vuln/detail/CVE-2024-7262
Related News Articles
APT-C-60 Hackers Exploit StatCounter and Bitbucket in SpyGlace Malware CampaignNovember 27, 2024
South Korean hackers exploited WPS Office zero-day to deploy malwareAugust 29, 2024
APT-C-60 Group Exploit WPS Office Flaw to Deploy SpyGlace BackdoorAugust 28, 2024
APT group exploits WPS Office for Windows RCE vulnerability (CVE-2024-7262)August 28, 2024