CVE-2022-26081: High severity wps office vulnerability
The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-26081?
CVE-2022-26081 is a vulnerability found in the installer of WPS Office Version 10.8.0.5745 that allows an attacker to execute arbitrary code with the user's privilege.
What is the severity of CVE-2022-26081?
The severity of CVE-2022-26081 is high, with a CVSS score of 7.8.
How does CVE-2022-26081 work?
CVE-2022-26081 works by insecurely loading the shcore.dll library during the WPS Office installer process, which can be exploited by an attacker to execute arbitrary code.
How can I fix CVE-2022-26081?
To fix CVE-2022-26081, update WPS Office to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2022-26081?
You can find more information about CVE-2022-26081 at the following references: [1] https://jvn.jp/en/jp/JVN21234459/ [2] https://support.kingsoft.jp/support-info/weakness.html