Back

CRITICAL KEV

Arbitrary Code Execution in WPS Office

Published Aug 15, 2024 ·Due Sep 24, 2024

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

Affected products

Remediation

Vendor solution

Update to latest version

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ESET
Published Aug 15, 2024
Updated Oct 21, 2025
Reserved Jul 30, 2024
CISA Vulnrichment
Updated Aug 31, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner ESET
Published Aug 15, 2024
Updated Oct 21, 2025
Exploited since Sep 3, 2024
EUVD-2024-48209