KEVIntel
9.3
CVSS
Critical

CVE-2024-7262

PUBLISHED

Arbitrary Code Execution in WPS Office

Exploited in the wild Low complexity
Vendor
Kingsoft
Product
WPS Office
Published
Aug 15, 2024
EPSS

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

windows cisa nessus_scanner

CVSS scores

CVSS v4.0 9.3 Critical

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:N/RE:L

Exploitation status

Exploited in the wild

Recorded 2024-09-03 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Sep 03, 2024

Scanner integrations

Scanner Reference Detected
Nessus https://www.tenable.com/plugins/nessus/206658 Jun 02, 2025

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus