Skip to content
COOEY

EXPOSURES › CVE-2024-7262

CVE-2024-7262

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-09-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-7262 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildrceunpatched

Kingsoft WPS Office allows arbitrary Windows library loading via path traversal in promecefpluginhost.exe, enabling remote code execution.

This vulnerability permits attackers to load arbitrary libraries in the WPS Office plugin host, creating a remote code execution (RCE) vector that bypasses standard sandboxing. DIB organizations must immediately patch WPS Office deployments to prevent unauthorized code execution and potential data exfiltration, as this flaw is actively exploited in the wild.

Shame score — The vendor shipped a critical RCE vulnerability in a widely used office suite that is actively exploited, indicating a failure in timely patching and security hardening.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.