← Back to CVE List
Vulnerability Intelligence Report
Arbitrary Code Execution in WPS Office

CVE-2024-11957

Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough.

No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-347 ↗CWE-347: Improper Verification of Cryptographic Signature

Affected Products & Versions

Vendor Product Affected Versions
Kingsoft WPS Office 12.2.0.16909 < 12.1.0.18276 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.104%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityESET, spol. s r.o. · Vendor · Slovak Republic
Reserved2024-11-28T07:42:29
Published2025-03-04T15:41:00
Last Updated2025-03-05T08:05:18

LINK COPIED TO CLIPBOARD