CVE-2024-7262
KEVmass1Path Traversal Arbitrary Library Load in Kingsoft WPS Office for Windows
CISA: Kingsoft WPS Office Path Traversal Vulnerability
CVE-2024-7262 is a path traversal flaw (CWE-22) caused by improper path validation in promecefpluginhost.exe in Kingsoft WPS Office for Windows, affecting versions from 12.2.0.13110 up to but not including 12.2.0.16412. It is triggered with a single user action: opening a deceptive, weaponized spreadsheet document causes the vulnerable component to load an arbitrary Windows library chosen by the attacker. Loading an attacker-controlled library yields code execution within WPS Office, making this an effective one-click remote code execution vector on Windows. Any Windows user running WPS Office in the affected version range is exposed, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03 with a required action of applying vendor mitigations or discontinuing use. Exploitation has been observed in the wild: ESET (the assigning CNA) and news coverage report that the APT-C-60 group used the then-zero-day in campaigns deploying the SpyGlace backdoor, with targeting linked to South Korea.
What to do: Upgrade WPS Office for Windows to version 12.2.0.16412 or later, since all builds from 12.2.0.13110 up to (but excluding) that version are vulnerable, and follow Kingsoft's vendor guidance; per CISA KEV, apply vendor mitigations or discontinue use if patching is not possible. Treat unsolicited spreadsheet documents as a delivery vector, and hunt for signs of APT-C-60/SpyGlace activity such as unexpected library loads by promecefpluginhost.exe.
| Kingsoft WPS Office for Windows | 12.2.0.13110 (inclusive) through 12.2.0.16412 (exclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document
- Affected
- Kingsoft WPS Office
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- kingsoft
- Products
- wps office
- Weakness
- CWE-22
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:L/U:X