PT-2022-11228 · Kingsoft · Wps Office
Icewall
+1
·
Published
2022-05-12
·
Updated
2022-05-23
·
CVE-2021-40399
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WPS Office version 11.2.0.10351
Description
A use-after-free condition can be triggered by a specially-crafted XLS file, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to exploit this issue.
Recommendations
For version 11.2.0.10351, consider avoiding the use of WPS Spreadsheets until a patch is available, and be cautious when opening XLS files from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wps Office