Vulnerability record · CVE-2024-7262 · published 15 August 2024
CVE-2024-7262: Kingsoft WPS Office path validation flaw enables arbitrary library loading
Kingsoft · Wps Office
Kingsoft WPS Office on Windows fails to properly validate paths in promecefpluginhost.exe, allowing an attacker to load an arbitrary Windows library. The flaw was observed weaponized as a single-click exploit delivered through a deceptive spreadsheet document, and it affects WPS Office versions from 12.2.0.13110 up to but not including 12.2.0.16412.
Description
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:
Automated analysis
critical priorityThe flaw is in CISA KEV with confirmed weaponized single-click exploitation and a CVSS 4.0 score of 9.3, making it an urgent patching priority.
What it is
Kingsoft WPS Office on Windows fails to properly validate paths in promecefpluginhost.exe, allowing an attacker to load an arbitrary Windows library. The flaw was observed weaponized as a single-click exploit delivered through a deceptive spreadsheet document, and it affects WPS Office versions from 12.2.0.13110 up to but not including 12.2.0.16412.
Impact
An attacker can execute arbitrary code in the context of the affected process, leading to full compromise of confidentiality, integrity, and availability on the victim's system. Because the exploit is single-click and weaponized, it poses a direct risk of malware installation or further lateral movement.
Attack surface
The vulnerability is reached locally through a crafted spreadsheet document that triggers promecefpluginhost.exe; the CVSS vector indicates no privileges are required but user interaction is passive (UI:P), meaning the victim must open or interact with the document. No remote network vector is described.
Exploitation
CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2024-09-03, confirming active exploitation in the wild. EPSS gives a 30-day probability of 0.02937 (86th percentile), and the description states it was found weaponized as a single-click exploit.
What to do
- Update Kingsoft WPS Office to version 12.2.0.16412 or later as directed by the vendor advisory.
- If immediate patching is not possible, follow CISA KEV required actions: apply vendor mitigations or discontinue use of the product until mitigations are available.
- Restrict execution of promecefpluginhost.exe or block untrusted spreadsheet documents from opening in WPS Office where feasible.
- Educate users not to open unexpected or unsolicited spreadsheet attachments, as the exploit relies on a deceptive document.
- Monitor for and isolate systems that have opened suspicious spreadsheets until they can be verified clean.
Detection
- Hunt for unusual child processes or library loads originating from promecefpluginhost.exe, especially DLLs loaded from user-writable directories.
- Monitor for WPS Office opening spreadsheet files from email attachments, downloads, or temporary folders followed by unexpected process creation.
- Review endpoint logs for path traversal patterns or references to promecefpluginhost.exe in command lines or file paths.
- Correlate CISA KEV status with asset inventory to identify unpatched WPS Office installations in the environment.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-7262 to the Known Exploited Vulnerabilities catalog on 3 September 2024 as "Kingsoft WPS Office Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.wps.com/whatsnew/pc/20240422/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-7262 | US Government Resource |
Track CVE-2024-7262 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-7262), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.