
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
The WPS Office (cn.wps.moffice_eng) application before version 17.0.0 for Android contains a path traversal vulnerability (CVE-2024-35205) that fails to properly sanitize filenames before processing them through external application interactions. This vulnerability affects over 500 million Android users and was discovered in May 2024 (Microsoft Blog).
The vulnerability arises from improper implementation of Android's content provider mechanism, which is designed for secure file sharing between applications. When WPS Office receives files from other applications, it fails to validate or sanitize filenames, allowing a malicious app to potentially overwrite existing native libraries used by WPS Office. This vulnerability is part of a broader pattern called the "Dirty Stream" attack, where a malicious app can declare a rogue version of the FileProvider class to share files with names controlled by the attacker (Microsoft Blog, Security Online).
The vulnerability could lead to arbitrary code execution and token theft. An attacker could potentially gain full control over the application's behavior, manipulate WPS Office to perform unauthorized actions, or access sensitive user data. The impact extends to potential compromise of user security through unauthorized access to online accounts (Security Online).
Users are strongly advised to update their WPS Office application to version 17.0.0 or above, which includes a fix for the CVE-2024-35205 vulnerability. Additionally, users should be cautious about the permissions they grant to applications and avoid installing software from unknown or untrusted sources (Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”