CVE Database
/

CVE-2024-11957

Back to search

CVE-2024-11957

Published: Mar 4, 2025

Modified: Mar 5, 2025

PUBLISHED

Description

Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough.

VendorProductVersions

Kingsoft

WPS Office

affected
12.2.0.16909 - < 12.1.0.18276

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now