CVE-2024-7262 is an improper path validation vulnerability in Kingsoft WPS Office for Windows (versions 12.2.0.13110 to 12.2.0.16412 exclusive) that allows attackers to load arbitrary Windows libraries. This vulnerability carries a high CVSS score of 7.8, indicating a high impact on confidentiality, integrity, and availability, and can be exploited with a single user interaction via a deceptive document. It is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community discussion and media coverage, including reports of its use by South Korean threat actors. While no public exploit code is available, its active exploitation and high FAUCET Risk Score of 99/100 underscore its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.0.13110, < 12.2.0.16412CPE matchmatch criteria | cpe:2.3:a:kingsoft:wps_office:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:L/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.