CVE-2024-7262
KINGSOFT JAPAN, INC. provides Kingsoft Office Software's WPS Office and its related products localized for Japan.<br /> WPS Office and its related products provided by KINGSOFT JAPAN, INC. contain a path traversal vulnerability (CWE-22, CVE-2024-7262, CVE-2024-7263)) due to inadequate file path validation by promecefpluginhost.exe.<br /> Note that, a report has been published describing that "WPS Office provided by Kingsoft Office Software is affected to this vulnerability and exploitation is observed".<br /> KINGSOFT JAPAN, INC. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and KINGSOFT JAPAN, INC. coordinated under the Information Security Early Warning Partnership.
EPSS 2.94% · 86.4th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| KINGSOFT, INC. | WPS Office2 for Windows | |
| KINGSOFT, INC. | WPS Cloud | |
| KINGSOFT, INC. | KINGSOFT PDF Pro | |
| KINGSOFT, INC. | WPS Cloud Pro |
Timeline
- CVE Published
- Feb 29, 2024 VulnCheck KEV Exploitation
- Aug 15, 2024 VulnCheck KEV Exploitation
- Aug 16, 2024 EPSS Score
- Aug 28, 2024 VulnCheck KEV Exploitation
- Sep 3, 2024 CISA KEV Added
- Sep 3, 2024 VulnCheck KEV Exploitation
- Sep 3, 2024 PoC Published
- Sep 4, 2024 EPSS Score
- Sep 12, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Nov 7, 2024 VulnCheck KEV Exploitation