CVE-2024-7263

Severity CVSS v4.0:
CRITICAL
Type:
CWE-22 Path Traversal
Publication date:
15/08/2024
Last modified:
24/04/2025

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows library.<br /> The patch released in version 12.1.0.17119 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kingsoft:wps_office:*:*:*:*:*:*:*:* 12.2.0.13110 (including) 12.2.0.17153 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools