Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows library.
The patch released in version 12.1.0.17119 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.wps.com/whatsnew/pc/20240422/ |
History
Thu, 22 Aug 2024 06:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17153 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized which leads to the execution of an arbitrary Windows library. | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.1.0.17119 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized which leads to the execution of an arbitrary Windows library. |
Fri, 16 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Microsoft
Microsoft windows |
|
CPEs | cpe:2.3:a:kingsoft:wps_office:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Microsoft
Microsoft windows |
|
Metrics |
cvssV3_1
|
Fri, 16 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Kingsoft
Kingsoft wps Office |
|
CPEs | cpe:2.3:a:kingsoft:wps_office:12.2.0.13110:*:*:*:*:*:*:* | |
Vendors & Products |
Kingsoft
Kingsoft wps Office |
|
Metrics |
ssvc
|
Fri, 16 Aug 2024 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library. | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17153 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized which leads to the execution of an arbitrary Windows library. |
Thu, 15 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library. | |
Title | Arbitrary Code Execution in WPS Office | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: ESET
Published: 2024-08-15T14:29:04.097Z
Updated: 2024-08-22T05:46:47.221Z
Reserved: 2024-07-30T07:50:57.690Z
Link: CVE-2024-7263
Vulnrichment
Updated: 2024-08-16T13:38:14.853Z
NVD
Status : Modified
Published: 2024-08-15T15:15:22.453
Modified: 2024-08-22T06:15:04.510
Link: CVE-2024-7263
Redhat
No data.