vendor:
WPS Office
by:
Francis Provencher of COSIG
8,8
CVSS
HIGH
Heap Memory Corruption
119
CWE
Product Name: WPS Office
Affected Version From: Version 2016
Affected Version To: Version 2016
Patch Exists: YES
Related CWE: N/A
CPE: a:kingsoft:wps_office
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2015
Heap Memory Corruption in WPS Office
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of WPS. User interaction is required to exploit this vulnerability in that the target must open a malicious file. By providing a malformed .xls file, an attacker can cause an heap memory corruption. An attacker could leverage this to execute arbitrary code under the context of the WPS Spreadshet application.
Mitigation:
Users should avoid opening untrusted files and should update to the latest version of WPS Office.