Vulnerability Intelligence Report
Arbitrary Code Execution in WPS Office
CVE-2024-11957
Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough.
No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-347 ↗CWE-347: Improper Verification of Cryptographic Signature
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Kingsoft | WPS Office | 12.2.0.16909 < 12.1.0.18276 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.104%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | ESET, spol. s r.o. · Vendor · Slovak Republic |
| Reserved | 2024-11-28T07:42:29 |
| Published | 2025-03-04T15:41:00 |
| Last Updated | 2025-03-05T08:05:18 |
Community Chatter & Buzz