CVE-2022-25969

HIGH

WPS Office <10.8.0.6186 - Code Injection

Title source: llm

Description

The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.

Scores

CVSS v3 7.8
EPSS 0.0037
EPSS Percentile 58.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

kingsoft/wps_office

Timeline

Published Mar 17, 2022
Tracked Since Feb 18, 2026