Kingsoft's vulnerability portfolio centers on a focused set of consumer and business productivity applications—principally its WPS Office suite and antivirus products—that rank among the more prominent targets in the landscape despite a modest overall product count. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of office and security utilities as attack vectors; vulnerabilities recur through memory-safety and path-handling weakness classes including buffer overflows, uncontrolled search-path resolution, and path-traversal conditions that are characteristic of applications handling file operations and user input. The exposure spans both productivity and security software, making patch coverage across both tiers a consideration for organizations running Kingsoft's products. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kingsoft over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7262HIGH Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arb | Aug 15, 2024 | 7.8 | 65 | YES | NO |
CVE-2008-1307HIGH Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to ex | Mar 12, 2008 | 10.0 | 49 | NO | YES |
CVE-2012-4886HIGH Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code via a long BSTR string. | Mar 24, 2014 | 10.0 | 48 | NO | YES |
CVE-2013-3934HIGH Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute arbitrary code via a long font | Sep 10, 2013 | 9.3 | 37 | NO | YES |
CVE-2010-3396HIGH Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argument to IOCTL 0x80030004. NOTE: some of t | Sep 15, 2010 | 7.2 | 30 | NO | YES |
CVE-2010-2031HIGH KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x8 | May 24, 2010 | 7.2 | 29 | NO | YES |
CVE-2024-7263HIGH Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arb | Aug 15, 2024 | 7.8 | 26 | NO | NO |
CVE-2022-26511HIGH WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading). | Mar 17, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-26081HIGH The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer. | Mar 17, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-25949HIGH The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading to stack-based buffer overflow. | Mar 17, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kingsoft.
Media articles that mention a CVE ID that affects a product developed by Kingsoft — matched by CVE ID, not by vendor name.