PT-2020-16068 · Kingsoft+1 · Kingsoft Wps Office+1

Published

2020-09-13

·

Updated

2020-10-05

·

CVE-2020-25291

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kingsoft WPS Office versions prior to 11.2.0.9403
Description The issue allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to the QBrush::setMatrix function in gui/painting/qbrush.cpp in Qt 4.x. The GdiDrawHoriLineIAlt function is also involved in this issue.
Recommendations For Kingsoft WPS Office versions prior to 11.2.0.9403, update to version 11.2.0.9403 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted PNG data within Word documents until the update is applied.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25291

Affected Products

Kingsoft Wps Office
Qt