CVE-2024-7263 is a high-severity improper path validation vulnerability in Kingsoft WPS Office for Windows, affecting versions 12.2.0.13110 to 12.2.0.17115. This flaw allows an attacker to load an arbitrary Windows library due to insufficient sanitization of a parameter, bypassing a previous patch for a similar vulnerability. With a CVSS score of 7.8, it presents a significant risk of high impact to confidentiality, integrity, and availability, requiring user interaction for exploitation. This vulnerability is actively exploited in the wild by South Korea-linked threat actors, as evidenced by multiple media reports, despite no public exploit code being available on platforms like Metasploit or ExploitDB. The vulnerability has garnered notable community discussion and media coverage, indicating its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.0.13110, < 12.2.0.17153CPE matchmatch criteria | cpe:2.3:a:kingsoft:wps_office:*:*:*:*:*:*:*:* | ||
>= 12.2.0.13110, < 12.2.0.17115CPE match | cpe:2.3:a:kingsoft:wps_office:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.