PT-2022-17613 · Kingsoft · Wps Office
Mohammed Hadi
·
Published
2022-03-09
·
Updated
2022-03-14
·
CVE-2022-25943
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WPS Office for Windows versions prior to v11.2.0.10258
Description
The issue is related to the installer of WPS Office for Windows, which fails to properly configure the Access Control List (ACL) for the directory where the service program is installed. This can potentially lead to security issues.
Recommendations
For versions prior to v11.2.0.10258, update to version v11.2.0.10258 or later to resolve the issue.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wps Office