CVE-2023-31275

HIGH

WPS Office 11.2.0.11537 - RCE

Title source: llm
STIX 2.1

Description

An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel file. A specially crafted malformed file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

Scores

CVSS v3 8.8
EPSS 0.0097
EPSS Percentile 76.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-457 CWE-908
Status published
Products (1)
kingsoft/wps_office 11.2.0.11537
Published Nov 27, 2023
Tracked Since Feb 18, 2026