peter bassill · operator
$ cve CVE-2024-7262 JSON

CVE-2024-7262 KEV

7.8
HIGH · CVSS 3.1 · EPSS 2.9% (pctl 87)

Patch first

On CISA KEV — known exploited in the wild, due 2024-09-24.

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS2.94% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2024-09-24
Public exploitnone known
Published2024-08-15
Last modified2026-06-17

CISA KEV

NameKingsoft WPS Office Path Traversal Vulnerability
Added2024-09-03
Due2024-09-24
Vendor / productKingsoft / WPS Office
Ransomware usenone reported

Affected (2)

VendorProduct
kingsoftwps office
microsoftwindows

References

→ the Explorer  ·  watch your stack  ·  NVD