Kingsoft WPS Office Path Traversal Vulnerability

北京赛克艾威科技有限公司 2024-09-03


  • 漏洞编号:CVE-2024-7262
  • 漏洞等级:严重
  • 漏洞标签:Kingsoft、WPS Office、在野利用
  • 发布时间:2024-09-03

漏洞描述

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.

修复建议

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

参考链接

While CISA cannot confirm the effectiveness of patches at this time, it is recommended that mitigations be applied per vendor instructions if available. If these instructions cannot be located or if mitigations are unavailable, discontinue the use of the product.

https://www.cisa.gov/known-exploited-vulnerabilities-catalog