PT-2022-1948 · Kingsoft · Wps Presentation

Eiji James Yoshida

·

Published

2022-01-06

·

Updated

2022-03-24

·

CVE-2022-26511

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPS Presentation version 11.8.0.5745
Description The issue is related to the insecure loading of the d3dx9 41.dll library when opening .pps files, specifically due to 'current directory type' DLL loading. This can allow an attacker to elevate privileges and execute arbitrary code.
Recommendations For WPS Presentation version 11.8.0.5745, consider restricting the loading of the d3dx9 41.dll library to prevent exploitation until a patch is available. As a temporary workaround, avoid opening .pps files from untrusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01505
CVE-2022-26511

Affected Products

Wps Presentation