CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2024-7262

CVSS 9.3v4.0pub. 2024-08-15upd. 2025-10-30

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

🤖 AI Analysis
How it works

The flaw lies in improper path validation in the promecefpluginhost.exe executable that is part of Kingsoft WPS Office. An attacker can provide the victim with a malicious spreadsheet document, which when opened (single click) causes the application to load any DLL library specified by the attacker. The path traversal mechanism allows bypassing the allowed directory and specifying a library located in any accessible location on the system or network.

Impact

An attacker can achieve arbitrary code execution in the context of the WPS Office process by loading a malicious Windows library, which in practice can result in complete takeover of the victim's system.

Mitigation & patch

Kingsoft WPS Office should be updated to version 12.2.0.16412 or newer. Detailed information about the patch is available in the vendor's references at https://www.wps.com/whatsnew/pc/20240422/

Who is affected

Kingsoft WPS Office versions from 12.2.0.13110 to 12.2.0.16412 (exclusive) running on Microsoft Windows system.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:L/U:X
  • Kingsoft Wps Office

    APP
    Kingsoft
    12.2.0.13110 – 12.2.0.16412 (excl.)
  • Microsoft Windows

    OS
    Microsoft
    all versions

CISA KEV — detailsi

Vendori
Kingsoft
Producti
WPS Office
Added to KEVi
September 3, 2024
Remediation deadline (US Federal)i
September 24, 2024(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 24 września 2024
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2024-4577CRITICAL9.8⚠ KEVPL ✓same product

PHP CGI argument injection – RCE na Windows przez mechanizm Best-Fit

CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez YAML deserialization w IBM Aspera Faspex