Vulnerability in Kingsoft “WPS Office”. Call for discontinuation and transition to subsequent products-PC Watch

2023-06-12 05:17:41

JVN, which is jointly operated by the JPCERT Coordination Center (JPCERT/CC) and the Information-technology Promotion Agency (IPA), is on the 12th.kingsoftThe company’s office suite “WPS Office” has an OS command injection vulnerability.

Targeting version 10.8.0.6186 of WPS Office, if a remote third party capable of man-in-the-middle attack connects this product to an unauthorized server and sends crafted data, the system where this product is installed may It is said that arbitrary OS commands may be executed on the computer.

Since WPS Office has already ended support by the manufacturer, we are calling for customers to stop using the product as a countermeasure and move to the follow-on product “WPS Office 2”.

1686553147
#Vulnerability #Kingsoft #WPS #Office #Call #discontinuation #transition #subsequent #productsPC #Watch

Leave a Replay