South Korean Spies Exploit WPS Office Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-7262 +1 in the same advisory: …7263 | Path Traversal Arbitrary Library Load in Kingsoft WPS Office for Windows CVE-2024-7262 is a path traversal flaw (CWE-22) caused by improper path validation in promecefpluginhost.exe in Kingsoft WPS Office for Windows, affecting versions from 12.2.0.13110 up to but not including 12.2.0.16412. It is triggered with a single user action: opening a deceptive, weaponized spreadsheet document causes the vulnerable component to load an arbitrary Windows library chosen by the attacker. Loading an attacker-controlled library yields code execution within WPS Office, making this an effective one-click remote code execution vector on Windows. Any Windows user running WPS Office in the affected version range is exposed, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-03 with a required action of applying vendor mitigations or discontinuing use. Exploitation has been observed in the wild: ESET (the assigning CNA) and news coverage report that the APT-C-60 group used the then-zero-day in campaigns deploying the SpyGlace backdoor, with targeting linked to South Korea. Do: Upgrade WPS Office for Windows to version 12.2.0.16412 or later, since all builds from 12.2.0.13110 up to (but excluding) that version are vulnerable, and follow Kingsoft's vendor guidance; per CISA KEV, apply vendor mitigations or discontinue use if patching is not possible. Treat unsolicited spreadsheet documents as a delivery vector, and hunt for signs of APT-C-60/SpyGlace activity such as unexpected library loads by promecefpluginhost.exe. | 9.3 | 3% | KEV |
| massplausibly tens of millions of Windows users (WPS Office's global user base is reported in the hundreds of millions, though only the 12.2.0.13110–12.2.0.16412… |
Full article353 words · extracted from infosecurity-magazine.com · click to collapse
ESET has revealed a new cyber-espionage campaign linked to a South Korean APT in which a novel remote code execution (RCE) vulnerability in WPS Office for Windows was exploited to deploy a custom backdoor.
Traced to the Seoul-aligned APT-C-60 group, the campaign targeted victims in East Asia with the “SpyGlace” backdoor, which is loaded with cyber-espionage capabilities.
Victims were persuaded to click on a legitimate-looking WPS Office for Windows spreadsheet, triggering the exploit. WPS Office has hundreds of millions of active users worldwide, especially in East Asia, ESET said.
The document itself was an MHTML export of the more common XLS spreadsheet format, booby-trapped with a hidden hyperlink designed to trigger the execution of an arbitrary library if clicked while using the WPS Spreadsheet app.
Read more on WPS Office threats: China-Aligned APT Group Blackwood Unleashes NSPX30 Implant
MHTML allows a file to be downloaded as soon as the document is opened, thus supporting RCE, ESET explained.
“To exploit this vulnerability, an attacker would need to store a malicious library somewhere accessible by the targeted computer either on the system or on a remote share, and know its file path in advance. The exploit developers targeting this vulnerability knew a couple of tricks that helped them achieve this,” explained ESET researcher Romain Dumont.
“When opening the spreadsheet document with the WPS Spreadsheet application, the remote library is automatically downloaded and stored on disk.”
Whomever developed the exploit embedded a picture of the spreadsheet’s rows and columns to make it appear legitimate. The malicious hyperlink was linked to the image so that clicking on a cell in the picture would trigger the exploit, ESET said.
The zero-day bug in question (CVE-2024-7262) was silently patched by WPS Office developer Kingsoft, according to ESET. However, the researchers discovered that it hadn’t fully remediated the issue, and found a subsequent vulnerability (CVE-2024-7263) which could enable hackers to achieve the same ends via improper input validation.
ESET claimed that Chinese-based DBAPPSecurity has independently published an analysis of the weaponized vulnerability and concluded that APT-C-60 exploited it to deliver malware to users in China.
Image credit: rafapress / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/south-korean-spies-exploit-wps/