Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough.
History

Tue, 04 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Mar 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough.
Title Arbitrary Code Execution in WPS Office
Weaknesses CWE-347
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published:

Updated: 2025-03-05T08:05:18.805Z

Reserved: 2024-11-28T07:42:29.586Z

Link: CVE-2024-11957

cve-icon Vulnrichment

Updated: 2025-03-04T16:07:15.524Z

cve-icon NVD

Status : Received

Published: 2025-03-04T16:15:34.927

Modified: 2025-03-04T16:15:34.927

Link: CVE-2024-11957

cve-icon Redhat

No data.