First published: Thu May 12 2022(Updated: )
An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPS Office | =11.2.0.10351 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40399 has been rated as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2021-40399, update WPS Office to version 11.2.0.10352 or later.
CVE-2021-40399 can lead to remote code execution, allowing attackers to execute arbitrary code on your system.
CVE-2021-40399 can be exploited using specially-crafted XLS files.
Users of WPS Office version 11.2.0.10351 are affected by CVE-2021-40399.