PT-2025-9677 · Kingsoft · Kingsoft Wps Office
Romain Dumont
·
Published
2025-03-04
·
Updated
2025-03-05
·
CVE-2024-11957
CVSS v4.0
9.3
Critical
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Kingsoft WPS Office versions prior to 12.2.0.16909
Description
The issue is related to improper verification of the digital signature in ksojscore.dll, allowing an attacker to load an arbitrary Windows library.
Recommendations
For versions prior to 12.2.0.16909, update to version 12.2.0.16909 or later to resolve the issue.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kingsoft Wps Office