VendorsKingsoftwps_office10.8.0.6186
Vulnerabilities

Kingsoft WPS Office 10.8.0.6186

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2023-32548
OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed.
Published 2023-06-13 · Modified
8.1EPSS 0.011
CVE-2022-25969
The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.
Published 2022-03-17 · Modified
7.8EPSS 0.008