CVE-2024-57096: Infoleak
Published May 14, 2025
·Updated
An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.
Affected Software
2 affected components
wps Office<19302
Kingsoft WPS Office
Event History
May 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-57096?
CVE-2024-57096 is rated as a medium severity vulnerability.
2
How do I fix CVE-2024-57096?
To mitigate CVE-2024-57096, ensure you update WPS Office to version 19302 or later.
3
What type of attack does CVE-2024-57096 allow?
CVE-2024-57096 allows a local attacker to obtain sensitive information through a crafted file.
4
Which versions of WPS Office are affected by CVE-2024-57096?
WPS Office version prior to 19302 is affected by CVE-2024-57096.
5
Is CVE-2024-57096 a local or remote vulnerability?
CVE-2024-57096 is a local vulnerability that requires physical access to the system.