Back to search
CVE-2022-25969
Published: Mar 17, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.
| Vendor | Product | Versions |
|---|---|---|
KINGSOFT JAPAN, INC. | The installer of WPS Office | affected Reported for Version 10.8.0.6186 |
Weaknesses (CWE)
References
https://support.kingsoft.jp/support-info/weakness.html
x_refsource_CONFIRM
JVN#21234459: Multiple vulnerabilities in KINGSOFT 'WPS Office' and 'KINGSOFT Internet Security'
third-party-advisory
x_refsource_JVN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now