Back to search
CVE-2022-25943
Published: Mar 9, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.
| Vendor | Product | Versions |
|---|---|---|
WPS Office Software | WPS Office for Windows | affected versions prior to v11.2.0.10258 |
Weaknesses (CWE)
References
https://www.wps.com/whatsnew/pc/20210806/
x_refsource_CONFIRM
JVNVU#90673830: Installer of WPS Office for Windows misconfigures the ACL for the installation directory
third-party-advisory
x_refsource_JVN
https://github.com/HadiMed/KINGSOFT-WPS-Office-LPE
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now