CVE-2022-25943: High severity wps office vulnerability
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25943?
CVE-2022-25943 is a vulnerability in WPS Office for Windows versions prior to v11.2.0.10258 that fails to configure the ACL for the installation directory.
How does CVE-2022-25943 affect WPS Office for Windows?
CVE-2022-25943 affects WPS Office for Windows versions prior to v11.2.0.10258 by improperly configuring the ACL for the directory where the service program is installed.
What is the severity of CVE-2022-25943?
CVE-2022-25943 has a severity rating of 7.8 (High).
How can I fix CVE-2022-25943?
To fix CVE-2022-25943, update WPS Office for Windows to version v11.2.0.10258 or later.
Where can I find more information about CVE-2022-25943?
You can find more information about CVE-2022-25943 at the following references: [GitHub](https://github.com/HadiMed/KINGSOFT-WPS-Office-LPE), [JVN](https://jvn.jp/en/vu/JVNVU90673830/), [WPS Office](https://www.wps.com/whatsnew/pc/20210806/).