ZeroHour

CVE-2022-25969

CVSS 3.1
7.8 high
EPSS
<1%p55
Published
()
Modified
Description

The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.

Vendors
kingsoft
Products
wps office
Weakness
CWE-427
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.