CVE-2021-40399: Use After Free
Published May 12, 2022
·Updated
An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
Affected Software
1 affected component
wps WPS Office=11.2.0.10351
Event History
May 12, 2022
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-40399?
CVE-2021-40399 has been rated as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2021-40399?
To fix CVE-2021-40399, update WPS Office to version 11.2.0.10352 or later.
3
What impact does CVE-2021-40399 have on my system?
CVE-2021-40399 can lead to remote code execution, allowing attackers to execute arbitrary code on your system.
4
What types of files can exploit CVE-2021-40399?
CVE-2021-40399 can be exploited using specially-crafted XLS files.
5
Who is affected by CVE-2021-40399?
Users of WPS Office version 11.2.0.10351 are affected by CVE-2021-40399.