CVE-2024-7262

Severity CVSS v4.0:
CRITICAL
Type:
CWE-22 Path Traversal
Publication date:
15/08/2024
Last modified:
30/10/2025

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library.<br /> The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kingsoft:wps_office:*:*:*:*:*:*:*:* 12.2.0.13110 (including) 12.2.0.16412 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*