Junglewise Threat Intelligence

CVE-2024-7262: Kingsoft WPS Office Path Traversal Vulnerability

CVE-2024-7262 · Severity: critical · CVSS 9.3 · Exploited in the wild · Published 2024-09-03

Executive brief

Kingsoft WPS Office for Windows contains a path traversal vulnerability in promecefpluginhost.exe due to improper path validation. An attacker can exploit this by tricking a user into clicking a crafted hyperlink in a deceptive spreadsheet, leading to the loading and execution of an arbitrary Windows library.

Affected products

  • Kingsoft WPS Office 12.2.0.13110 to 12.2.0.16412 (exclusive)

Timeline

  • 2024-08-15: disclosed: NVD Published Date
  • 2024-08-15: other: New CVE received from ESET
  • 2024-09-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-03: advisory: CISA-ADP advisory published