CVE-2022-26081
HIGHWPS Office <10.8.0.5745 - Code Injection
Title source: llmDescription
The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.
Scores
CVSS v3
7.8
EPSS
0.0037
EPSS Percentile
58.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
kingsoft/wps_office
Timeline
Published
Mar 17, 2022
Tracked Since
Feb 18, 2026