← Back to CVE List
Vulnerability Intelligence Report
Arbitrary Code Execution in WPS Office

CVE-2024-7262

x_known-exploited-vulnerability

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

CISA KEV SSVC: Active Exploitation
CVSS Base Score
9.3
CRITICAL
EPSS Probability:1.76%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22: Improper Limitation of a Pathname to a Restricted Directory

Affected Products & Versions

Vendor Product Affected Versions
Kingsoft WPS Office 12.2.0.13110 < 12.2.0.16412 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
1.759%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityESET, spol. s r.o. · Vendor · Slovak Republic
Reserved2024-07-30T07:50:53
Published2024-08-15T14:24:44
Last Updated2025-10-21T22:55:47

LINK COPIED TO CLIPBOARD