LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-7262: Kingsoft WPS Office Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 3, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 24, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-7262 to its Known Exploited Vulnerabilities catalog on Sep 3, 2024, with a federal patch deadline of Sep 24, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.

CVE-2024-7262 is a path traversal vulnerability in Kingsoft WPS Office on Windows. It affects the component promecefpluginhost.exe and can allow an attacker to load an arbitrary Windows library. For IT and security teams, this matters because successful abuse of such a flaw can lead to code execution under the context of the affected process, potentially enabling further compromise of the host. Confirm all product-specific details against the vendor advisory.

CISA notes that organizations should apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Known ransomware use is not documented for this CVE.

How it works

This issue is classified as CWE-22, Improper Limitation of a Pathname to a Restricted Directory (Path Traversal). In path traversal flaws, software fails to properly sanitize user-controlled input that influences file or path operations, allowing an attacker to escape intended directories and reach locations outside the expected scope.

According to the CISA summary, the vulnerability resides in promecefpluginhost.exe within Kingsoft WPS Office on Windows. An attacker can abuse the path traversal to cause the process to load an arbitrary Windows library. In general terms for this class of weakness, that typically means the attacker supplies a crafted path (for example, using sequences that navigate outside a restricted directory) so that a library of their choosing is loaded instead of a legitimate one. Exact exploit mechanics, required input format, and any preconditions are not detailed here and must be confirmed against the vendor advisory. No exploit code or specific attack chain is provided in the available facts.

Am I affected? How to find it in your systems

Kingsoft WPS Office is a productivity suite commonly installed on Windows endpoints in both enterprise and consumer environments. The vulnerable component is promecefpluginhost.exe. Inventory efforts should focus on Windows systems that have WPS Office installed.

For signs of exploitation, look for unusual library loads or process behavior associated with promecefpluginhost.exe. Endpoint detection and response (EDR) telemetry that records module loads, process creation, or file access outside expected WPS directories may surface anomalies. Windows event logs related to image loads or application errors involving that executable can also be useful. Correlate any such activity with unexpected network connections or subsequent process launches. Absence of public indicators of compromise in the given facts means teams should rely on behavioral detection and vendor guidance.

How to remediate

The primary remediation is to apply the vendor-supplied update that addresses CVE-2024-7262. Follow the instructions in the Kingsoft WPS Office advisory for the correct patch or newer release. After installation, verify that promecefpluginhost.exe has been replaced or updated as expected and re-inventory systems to confirm coverage.

In addition to patching:

CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Document the remediation status for audit and compliance purposes.

If you can't patch immediately

When immediate patching is not feasible, implement compensating controls to reduce exposure:

These measures do not eliminate the vulnerability but can lower the likelihood and impact of successful exploitation. Revisit the vendor advisory regularly for any additional interim guidance.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches in which sensitive data is accessed or exfiltrated. Although known ransomware use is not documented for CVE-2024-7262, any successful library load could enable further attacker activity. If you suspect compromise, follow your incident response plan: isolate affected hosts, preserve forensic evidence, and investigate for lateral movement or data access. Readers can run a free exposure scan of their email to check known breach data and determine whether associated accounts appear in public breach corpora. Confirm any specific indicators or post-exploitation guidance against the vendor advisory and your own telemetry.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedKingsoft · WPS Office
WeaknessCWE-22
Added to CISA KEVSep 3, 2024
Federal patch deadlineSep 24, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities