ZeroHour

CVE-2024-7262

KEVmass1

Path Traversal Arbitrary Library Load in Kingsoft WPS Office for Windows

CISA: Kingsoft WPS Office Path Traversal Vulnerability

CVSS 4.0
9.3 critical
EPSS
3%p86
Published
()
KEV added
AI analysis

CVE-2024-7262 is a path traversal flaw (CWE-22) caused by improper path validation in promecefpluginhost.exe in Kingsoft WPS Office for Windows, affecting versions from 12.2.0.13110 up to but not including 12.2.0.16412. It is triggered with a single user action: opening a deceptive, weaponized spreadsheet document causes the vulnerable component to load an arbitrary Windows library chosen by the attacker. Loading an attacker-controlled library yields code execution within WPS Office, making this an effective one-click remote code execution vector on Windows. Any Windows user running WPS Office in the affected version range is exposed, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03 with a required action of applying vendor mitigations or discontinuing use. Exploitation has been observed in the wild: ESET (the assigning CNA) and news coverage report that the APT-C-60 group used the then-zero-day in campaigns deploying the SpyGlace backdoor, with targeting linked to South Korea.

What to do: Upgrade WPS Office for Windows to version 12.2.0.16412 or later, since all builds from 12.2.0.13110 up to (but excluding) that version are vulnerable, and follow Kingsoft's vendor guidance; per CISA KEV, apply vendor mitigations or discontinue use if patching is not possible. Treat unsolicited spreadsheet documents as a delivery vector, and hunt for signs of APT-C-60/SpyGlace activity such as unexpected library loads by promecefpluginhost.exe.

Affected
Kingsoft WPS Office for Windows12.2.0.13110 (inclusive) through 12.2.0.16412 (exclusive)
Estimated exposure
massplausibly tens of millions of Windows users (WPS Office's global user base is reported in the hundreds of millions, though only the 12.2.0.13110–12.2.0.16412… — WPS Office is one of the most widely deployed office suites worldwide with a publicly claimed user base of hundreds of millions, so even a narrow Windows version range plausibly exposes an order of millions to tens of millions of users.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

CISA Known Exploited Vulnerability
Affected
Kingsoft WPS Office
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
kingsoft
Products
wps office
Weakness
CWE-22
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:L/U:X

In the news