CVE-2022-25969
Kingsoft WPS Office vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2022-25969) affects the installer of WPS Office Version 10.8.0.6186. It involves an insecure DLL loading issue that was discovered and reported on March 14, 2022. The vulnerability specifically relates to the insecure loading of VERSION.DLL and other DLLs during the installation process (CVE Mitre, JVN Report).

Technical details

The vulnerability is classified as an insecure DLL loading issue (CWE-427). According to the technical assessment, the CVSS v3 base score is 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The vulnerability specifically occurs when the WPS Office installer insecurely loads VERSION.DLL or other DLLs during the installation process (JVN Report).

Impact

When exploited, this vulnerability allows an attacker to execute arbitrary code with the privilege level of the user invoking the installer. This means that if a user with administrative privileges runs the installer, the attacker could potentially execute code with those elevated privileges (JVN Report).

Mitigation and workarounds

KINGSOFT JAPAN, INC. has addressed this vulnerability in newer versions of the software. Users are recommended to upgrade to WPS Office2 for Windows version 11.82.8498 or later versions, which was released in May 2020. The developer has confirmed that the vulnerability has been resolved in these updated versions (Kingsoft Support, JVN Report).

Additional resources


SourceThis report was generated using AI

Related Kingsoft WPS Office vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-7263CRITICAL9.3
  • Kingsoft WPS OfficeKingsoft WPS Office
  • cpe:2.3:a:kingsoft:wps_office
NoYesAug 15, 2024
CVE-2024-7262CRITICAL9.3
  • Kingsoft WPS OfficeKingsoft WPS Office
  • cpe:2.3:a:kingsoft:wps_office
YesYesAug 15, 2024
CVE-2024-35205HIGH7.8
  • Kingsoft WPS OfficeKingsoft WPS Office
  • cpe:2.3:a:kingsoft:wps_office
NoYesMay 14, 2024
CVE-2024-57096MEDIUM5.5
  • Kingsoft WPS OfficeKingsoft WPS Office
  • cpe:2.3:a:kingsoft:wps_office
NoYesMay 14, 2025
CVE-2024-13187MEDIUM4.8
  • Kingsoft WPS OfficeKingsoft WPS Office
  • cpe:2.3:a:kingsoft:wps_office
NoNoJan 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management