U.S. CISA adds Draytek VigorConnect and Kingsoft WPS Office bugs to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-20124 +1 in the same advisory: …20123 | Unauthenticated Path Traversal File Download in DrayTek VigorConnect CVE-2021-20124 is a path traversal (local file inclusion, CWE-22) flaw in the file download functionality of the WebServlet endpoint in DrayTek VigorConnect 1.6.0-B3, the vendor's on-premises centralized management software for Vigor networking equipment. Because the affected endpoint requires no authentication, any attacker who can reach the VigorConnect web interface over a network can send crafted requests that traverse outside the intended download directory. The VigorConnect service runs with root privileges on the underlying operating system, so an attacker can download arbitrary files with root-level access, potentially exposing credentials, configuration data, and other sensitive information on the management host. Any organization running DrayTek VigorConnect is affected, with the flaw confirmed in version 1.6.0-B3. The bug was publicly documented by Tenable (TRA-2021-42) in 2021 and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03 amid reports of active exploitation of DrayTek devices. Do: Upgrade DrayTek VigorConnect to a fixed release newer than 1.6.0-B3 per DrayTek's security guidance; if patching is delayed, restrict the VigorConnect web interface (WebServlet endpoint) to trusted management networks only. Because the flaw is on CISA's KEV catalog (added 2024-09-03) with active exploitation reported, review firewall and web-server logs for unauthenticated file-download requests against WebServlet, and rotate any credentials, keys, or configuration secrets stored on the management host that could have been exfiltrated. Organizations unable to obtain mitigations should consider discontinuing use of the product per CISA's required action. | 7.5 | 96% | KEV PoC |
| moderatelikely on the order of thousands of on-premises VigorConnect management-server deployments worldwide (estimate; no public install counts provided) | |
| CVE-2024-7262 | Path Traversal Arbitrary Library Load in Kingsoft WPS Office for Windows CVE-2024-7262 is a path traversal flaw (CWE-22) caused by improper path validation in promecefpluginhost.exe in Kingsoft WPS Office for Windows, affecting versions from 12.2.0.13110 up to but not including 12.2.0.16412. It is triggered with a single user action: opening a deceptive, weaponized spreadsheet document causes the vulnerable component to load an arbitrary Windows library chosen by the attacker. Loading an attacker-controlled library yields code execution within WPS Office, making this an effective one-click remote code execution vector on Windows. Any Windows user running WPS Office in the affected version range is exposed, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03 with a required action of applying vendor mitigations or discontinuing use. Exploitation has been observed in the wild: ESET (the assigning CNA) and news coverage report that the APT-C-60 group used the then-zero-day in campaigns deploying the SpyGlace backdoor, with targeting linked to South Korea. Do: Upgrade WPS Office for Windows to version 12.2.0.16412 or later, since all builds from 12.2.0.13110 up to (but excluding) that version are vulnerable, and follow Kingsoft's vendor guidance; per CISA KEV, apply vendor mitigations or discontinue use if patching is not possible. Treat unsolicited spreadsheet documents as a delivery vector, and hunt for signs of APT-C-60/SpyGlace activity such as unexpected library loads by promecefpluginhost.exe. | 9.3 | 3% | KEV |
| massplausibly tens of millions of Windows users (WPS Office's global user base is reported in the hundreds of millions, though only the 12.2.0.13110–12.2.0.16412… |
Full article371 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 07, 2024

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Draytek VigorConnect and Kingsoft WPS Office bugs to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Draytek VigorConnect and Kingsoft WPS Office vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the descriptions for these vulnerabilities:
- CVE-2021-20123 Draytek VigorConnect Path Traversal Vulnerability: A local file inclusion issue in Draytek VigorConnect 1.6.0-B3 allows unauthenticated attackers to exploit the file download functionality of the DownloadFileServlet endpoint. This flaw enables attackers to download arbitrary files from the underlying operating system with root privileges, posing a significant security risk.
- CVE-2021-20124 Draytek VigorConnect Path Traversal Vulnerability: A local file inclusion vulnerability in Draytek VigorConnect 1.6.0-B3 affects the WebServlet endpoint’s file download functionality. This flaw allows unauthenticated attackers to download arbitrary files from the underlying operating system with root privileges, posing a serious security threat.
- CVE-2024-7262 Kingsoft WPS Office Path Traversal Vulnerability: An improper path validation vulnerability in Kingsoft WPS Office (versions 12.2.0.13110 to 12.2.0.16412) allows attackers to load arbitrary Windows libraries via the promecefpluginhost.exe. This flaw has been weaponized in a single-click exploit, delivered through a deceptive spreadsheet document.
At the end of August, Eset researchers reported that South Korea-linked group APT-C-60 exploited a zero-day, tracked as CVE-2024-7262, in the Windows version of WPS Office to deploy the SpyGlace backdoor in the systems on targets in East Asia.
WPS Office is a comprehensive office productivity suite developed by Chinese software company Kingsoft and is widely used in Asia. It provides users with a range of tools for creating, editing, and managing documents, spreadsheets, presentations, and PDFs.
According to the WPS website, WPS Office has over 500 million active users worldwide.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by September 24, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/168153/security/cisa-draytek-vigorconnect-kingsoft-wps-office-bugs-known-exploited-vulnerabilities-catalog.html