CVE-2022-24934: Critical severity wps office vulnerability
Published Mar 23, 2022
·Updated
wpsupdater.exe in Kingsoft WPS Office through 11.2.0.10382 allows remote code execution by modifying HKEYCURRENTUSER in the registry.
Affected Software
1 affected component
wps WPS Office<=11.2.0.10382
Event History
Mar 23, 2022
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
Description
Frequently Asked Questions
1
What is CVE-2022-24934?
CVE-2022-24934 is a vulnerability in Kingsoft WPS Office that allows remote code execution by modifying the registry.
2
How severe is CVE-2022-24934?
CVE-2022-24934 has a severity rating of 9.8, which is classified as critical.
3
Which versions of Kingsoft WPS Office are affected by CVE-2022-24934?
Kingsoft WPS Office versions up to and including 11.2.0.10382 are affected by CVE-2022-24934.
4
How can CVE-2022-24934 be exploited?
CVE-2022-24934 can be exploited by modifying HKEY_CURRENT_USER in the registry.
5
Is there any patch or fix available for CVE-2022-24934?
At the moment, there is no information available about a patch or fix for CVE-2022-24934. It is recommended to follow the vendor's security advisories for updates.