216.73.217.22

CVE-2024-7263

· Published 15/08/2024 17:15 · Modified 21/12/2025 14:26 · Author: The MITRE Corporation

Labels: CVE-2024-7263 2024-08-15CVE-2024-7263CWE-22[email protected]

Essential information

Published
15/08/2024 17:15
Modified
21/12/2025 14:26
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/C:H/I:H/A:H

CVSS metrics

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.1.0.17119 to mitigate CVE-2024-7262 was not restrictive enough. Another parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References