← Back to browse · API

CVE-2024-7262

Severity
CRITICAL
CVSS
9.3
EPSS
0.01773
Risk score
62.82
CISA KEV
Yes
PoC
No
Published
2024-08-15
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-48209, GHSA-P736-FP6Q-QR5J
Products
Kingsoft:WPS Office, WPS:WPS Office 12.2.0.13110 <12.2.0.16412
Sources
cisa.gov CVE-2024-7262
euvd EUVD-2024-48209

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

References