VDB

CVE-2024-7262

CVE-2024-7262 PUBLISHED KEV CVSS 7.800000190734863 HIGH

KINGSOFT JAPAN, INC. provides Kingsoft Office Software&#39;s WPS Office and its related products localized for Japan.<br /> WPS Office and its related products provided by KINGSOFT JAPAN, INC. contain a path traversal vulnerability (CWE-22, CVE-2024-7262, CVE-2024-7263)) due to inadequate file path validation by promecefpluginhost.exe.<br /> Note that, a report has been published describing that &quot;WPS Office&nbsp;provided by Kingsoft Office Software is affected to this vulnerability and exploitation is observed&quot;.<br /> KINGSOFT JAPAN, INC. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and KINGSOFT JAPAN, INC. coordinated under the Information Security Early Warning Partnership.

EPSS 2.94% · 86.4th percentile

Risk Scores

CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
2.94%
86.4th percentile

Affected Products

VendorProductVersions
KINGSOFT, INC.WPS Office2 for Windows
KINGSOFT, INC.WPS Cloud
KINGSOFT, INC.KINGSOFT PDF Pro
KINGSOFT, INC.WPS Cloud Pro

Timeline

  • CVE Published
  • Feb 29, 2024 VulnCheck KEV Exploitation
  • Aug 15, 2024 VulnCheck KEV Exploitation
  • Aug 16, 2024 EPSS Score
  • Aug 28, 2024 VulnCheck KEV Exploitation
  • Sep 3, 2024 CISA KEV Added
  • Sep 3, 2024 VulnCheck KEV Exploitation
  • Sep 3, 2024 PoC Published
  • Sep 4, 2024 EPSS Score
  • Sep 12, 2024 EPSS Score
  • Oct 5, 2024 Coalition ESS Score
  • Nov 7, 2024 VulnCheck KEV Exploitation
Open in Interactive Console →
$ Console Community · 100/wk Open console ›