Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kingsoft

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 25
61.3
VTI Score
TOP TARGET

Kingsoft's vulnerability portfolio centers on a focused set of consumer and business productivity applications—principally its WPS Office suite and antivirus products—that rank among the more prominent targets in the landscape despite a modest overall product count. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of office and security utilities as attack vectors; vulnerabilities recur through memory-safety and path-handling weakness classes including buffer overflows, uncontrolled search-path resolution, and path-traversal conditions that are characteristic of applications handling file operations and user input. The exposure spans both productivity and security software, making patch coverage across both tiers a consideration for organizations running Kingsoft's products. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
4.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Kingsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
May 14, 2025
436 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-7262HIGH
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arb
Aug 15, 20247.865YESNO
CVE-2008-1307HIGH
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to ex
Mar 12, 200810.049NOYES
CVE-2012-4886HIGH
Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code via a long BSTR string.
Mar 24, 201410.048NOYES
CVE-2013-3934HIGH
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute arbitrary code via a long font
Sep 10, 20139.337NOYES
CVE-2010-3396HIGH
Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argument to IOCTL 0x80030004. NOTE: some of t
Sep 15, 20107.230NOYES
CVE-2010-2031HIGH
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x8
May 24, 20107.229NOYES
CVE-2024-7263HIGH
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arb
Aug 15, 20247.826NONO
CVE-2022-26511HIGH
WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).
Mar 17, 20227.825NONO
CVE-2022-26081HIGH
The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.
Mar 17, 20227.825NONO
CVE-2022-25949HIGH
The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading to stack-based buffer overflow.
Mar 17, 20227.825NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
24%
68%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local13 (52.0%)
Network1 (4.0%)
Unknown11 (44.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (52.0%)
High1 (4.0%)
Unknown11 (44.0%)
User Interaction
None6 (24.0%)
Unknown11 (44.0%)
Required8 (32.0%)
Privileges Required
Low5 (20.0%)
High0 (0.0%)
None9 (36.0%)
Unknown11 (44.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
1 CVE
4.0% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
24.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kingsoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kingsoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kingsoft's Products

View all 4 CNAs →

Top CWEs