The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components. As older versions of WPS Office did not validate the update server's certificate, an Adversary-In-The-Middle attack was possible allowing updates to be hijacked.
History

Thu, 27 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Description The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components. As older versions of WPS Office did not validate the update server's certificate, an Adversary-In-The-Middle attack was possible allowing updates to be hijacked.
Title Use of a weak cryptographic key in the signature verification process in WPS Office
Weaknesses CWE-326
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ESET

Published:

Updated: 2025-03-27T15:15:56.127Z

Reserved: 2025-03-19T07:49:48.800Z

Link: CVE-2025-2516

cve-icon Vulnrichment

Updated: 2025-03-27T15:15:18.784Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-27T15:16:01.280

Modified: 2025-03-27T16:45:12.210

Link: CVE-2025-2516

cve-icon Redhat

No data.