
CVE-2025-2516 – Use of a weak cryptographic key in the signature verification process in WPS Office
https://notcve.org/view.php?id=CVE-2025-2516
27 Mar 2025 — The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components. As older versions of WPS Office did not validate the update server's certificate, an Adversary-In-The-Middle attack was possible allowing updates to be hijacked. • https://www.welivesecurity.com/en/eset-research/nspx30-sophisticated-aitm-enabled-implant-evolving-since-2005 • CWE-326: Inadequate Encryption Strength •

CVE-2024-11957 – Arbitrary Code Execution in WPS Office
https://notcve.org/view.php?id=CVE-2024-11957
04 Mar 2025 — Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12.1.0.18276 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. • https://www.welivesecurity.com/en/eset-research/analysis-of-two-arbitrary-code-execution-vulnerabilities-affecting-wps-office • CWE-347: Improper Verification of Cryptographic Signature •

CVE-2024-13187 – Kingsoft WPS Office TCC code injection
https://notcve.org/view.php?id=CVE-2024-13187
08 Jan 2025 — A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TCC Handler. The manipulation leads to code injection. It is possible to launch the attack on the local host. • https://github.com/Rsec-1/wps • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2024-7263 – Arbitrary Code Execution in WPS Office
https://notcve.org/view.php?id=CVE-2024-7263
15 Aug 2024 — Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library. Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.1311... • https://www.wps.com/whatsnew/pc/20240422 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2024-7262 – Kingsoft WPS Office Path Traversal Vulnerability
https://notcve.org/view.php?id=CVE-2024-7262
15 Aug 2024 — Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library. Using the MHTML format allows an attacker to automatically deliver a malicious library on opening the document and a single user click on a crafted hyperlink leads to the execution of the library. Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412... • https://www.wps.com/whatsnew/pc/20240422 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2023-31275
https://notcve.org/view.php?id=CVE-2023-31275
27 Nov 2023 — An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability. Existe una vulnerabilidad de uso de puntero no inicializado en la funcionalidad de WPS Office 11.2.0.11537 que maneja elementos de datos en un archivo de Excel. Un archivo con formato incorrecto especialmente manipulado puede p... • https://talosintelligence.com/vulnerability_reports/TALOS-2023-1748 • CWE-457: Use of Uninitialized Variable CWE-908: Use of Uninitialized Resource •

CVE-2023-32548
https://notcve.org/view.php?id=CVE-2023-32548
13 Jun 2023 — OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed. • https://jvn.jp/en/jp/JVN36060509 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVE-2022-26511
https://notcve.org/view.php?id=CVE-2022-26511
17 Mar 2022 — WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading). WPS Presentation versión 11.8.0.5745, una carga de forma no segura de d3dx9_41.dll cuando son abiertos archivos .pps("current directory type" carga DLL) • https://jvn.jp/en/jp/JVN21234459 • CWE-427: Uncontrolled Search Path Element •

CVE-2022-26081
https://notcve.org/view.php?id=CVE-2022-26081
17 Mar 2022 — The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer. El instalador de WPS Office versión 10.8.0.5745, carga de forma no segura de shcore.dll, lo que permite a un atacante ejecutar código arbitrario con el privilegio del usuario invocando a el instalador • https://jvn.jp/en/jp/JVN21234459 • CWE-427: Uncontrolled Search Path Element •

CVE-2022-25969
https://notcve.org/view.php?id=CVE-2022-25969
17 Mar 2022 — The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer. El instalador de WPS Office Versión 10.8.0.6186, una carga no segura de VERSION.DLL (o algunas otras DLL), permitiendo a un atacante ejecutar código arbitrario con el privilegio del usuario invocando a el instalador • https://jvn.jp/en/jp/JVN21234459 • CWE-427: Uncontrolled Search Path Element •