CVE-2024-35205: Path Traversal
The WPS Office (aka cn.wps.mofficeeng) application before 17.0.0 for Android fails to properly sanitize file names before processing them through external application interactions, leading to a form of path traversal. This potentially enables any application to dispatch a crafted library file, aiming to overwrite an existing native library utilized by WPS Office. Successful exploitation could result in the execution of arbitrary commands under the guise of WPS Office's application ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35205?
CVE-2024-35205 is classified as a high severity vulnerability due to its potential impact on user data and device integrity.
How do I fix CVE-2024-35205?
To mitigate CVE-2024-35205, users should update to WPS Office version 17.0.0 or later where the vulnerability has been addressed.
What applications are affected by CVE-2024-35205?
CVE-2024-35205 affects WPS Office for Android versions prior to 17.0.0.
What type of vulnerability is CVE-2024-35205?
CVE-2024-35205 is a path traversal vulnerability that occurs due to inadequate sanitization of file names.
What are the potential risks of CVE-2024-35205?
The risks associated with CVE-2024-35205 include unauthorized access to files and the potential execution of malicious code via crafted library files.