CVE-2024-13187: Kingsoft WPS Office TCC code injection
A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TCC Handler. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13187?
CVE-2024-13187 has been declared as critical due to its potential for code injection.
How do I fix CVE-2024-13187?
To fix CVE-2024-13187, you should update Kingsoft WPS Office to the latest version provided by the vendor.
What are the potential impacts of CVE-2024-13187?
The impact of CVE-2024-13187 includes unauthorized code execution on the local host.
Which versions of Kingsoft WPS Office are affected by CVE-2024-13187?
CVE-2024-13187 affects Kingsoft WPS Office version 6.14.0 on macOS.
What is the attack vector for CVE-2024-13187?
The attack vector for CVE-2024-13187 is local, allowing an attacker to manipulate TCC Handler functionality.