← Vulnerability feed

Vulnerability record · CVE-2024-7262 · published 15 August 2024

CVE-2024-7262: Kingsoft WPS Office path validation flaw enables arbitrary library loading

Kingsoft · Wps Office

Kingsoft WPS Office on Windows fails to properly validate paths in promecefpluginhost.exe, allowing an attacker to load an arbitrary Windows library. The flaw was observed weaponized as a single-click exploit delivered through a deceptive spreadsheet document, and it affects WPS Office versions from 12.2.0.13110 up to but not including 12.2.0.16412.

9.3 CVSS 4.0 Critical CISA KEV since 3 Sep 2024 EPSS 2.9% · top 13.4% CWE-22 · Path traversal
9.3CVSS 4.0 base score
2.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponized as a single-click exploit in the form of a deceptive spreadsheet document

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is in CISA KEV with confirmed weaponized single-click exploitation and a CVSS 4.0 score of 9.3, making it an urgent patching priority.

What it is

Kingsoft WPS Office on Windows fails to properly validate paths in promecefpluginhost.exe, allowing an attacker to load an arbitrary Windows library. The flaw was observed weaponized as a single-click exploit delivered through a deceptive spreadsheet document, and it affects WPS Office versions from 12.2.0.13110 up to but not including 12.2.0.16412.

Impact

An attacker can execute arbitrary code in the context of the affected process, leading to full compromise of confidentiality, integrity, and availability on the victim's system. Because the exploit is single-click and weaponized, it poses a direct risk of malware installation or further lateral movement.

Attack surface

The vulnerability is reached locally through a crafted spreadsheet document that triggers promecefpluginhost.exe; the CVSS vector indicates no privileges are required but user interaction is passive (UI:P), meaning the victim must open or interact with the document. No remote network vector is described.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2024-09-03, confirming active exploitation in the wild. EPSS gives a 30-day probability of 0.02937 (86th percentile), and the description states it was found weaponized as a single-click exploit.

What to do

  • Update Kingsoft WPS Office to version 12.2.0.16412 or later as directed by the vendor advisory.
  • If immediate patching is not possible, follow CISA KEV required actions: apply vendor mitigations or discontinue use of the product until mitigations are available.
  • Restrict execution of promecefpluginhost.exe or block untrusted spreadsheet documents from opening in WPS Office where feasible.
  • Educate users not to open unexpected or unsolicited spreadsheet attachments, as the exploit relies on a deceptive document.
  • Monitor for and isolate systems that have opened suspicious spreadsheets until they can be verified clean.

Detection

  • Hunt for unusual child processes or library loads originating from promecefpluginhost.exe, especially DLLs loaded from user-writable directories.
  • Monitor for WPS Office opening spreadsheet files from email attachments, downloads, or temporary folders followed by unexpected process creation.
  • Review endpoint logs for path traversal patterns or references to promecefpluginhost.exe in command lines or file paths.
  • Correlate CISA KEV status with asset inventory to identify unpatched WPS Office installations in the environment.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-7262 to the Known Exploited Vulnerabilities catalog on 3 September 2024 as "Kingsoft WPS Office Path Traversal Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 24 September 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7262 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2024-7263Kingsoft wps office path traversal vulnerabilityImproper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows al…EPSS 0.39%8.1CVE-2023-32548Kingsoft wps office os command injection vulnerabilityOS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects…EPSS 1.1%7.8CVE-2023-31275Kingsoft wps office use of uninitialized resource vulnerabilityAn uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A spec…EPSS 1.7%7.8CVE-2022-25969Kingsoft wps office uncontrolled search path element vulnerabilityThe installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with…EPSS 0.83%7.8CVE-2022-26081Kingsoft wps office uncontrolled search path element vulnerabilityThe installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the …EPSS 0.83%7.8CVE-2022-25943Kingsoft wps office incorrect default permissions vulnerabilityThe installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service progr…EPSS 0.72%7.8CVE-2020-25291Kingsoft wps office out-of-bounds write vulnerabilityGdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word docume…EPSS 1.6%5.5CVE-2024-57096Kingsoft wps office information exposure vulnerabilityAn issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.EPSS 0.16%

Source: NIST National Vulnerability Database (record CVE-2024-7262), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.