[Japanese]

JVNDB-2022-000021

Multiple vulnerabilities in KINGSOFT "WPS Office" and "KINGSOFT Internet Security"

Overview

"WPS Office" and "KINGSOFT Internet Security" provided by KINGSOFT JAPAN, INC. contain multiple vulnerabilities listed below.
* Stack-based buffer overflow (CWE-121) - CVE-2022-25949
* Insecurely loading Dynamic Link Libraries (CWE-427) - CVE-2022-26081, CVE-2022-25969, CVE-2022-26511

These vulnerabilities are reported by the following reporters, and
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2022-26949: Satoshi Tanda
CVE-2022-26081, CVE-2022-26511: Eiji James Yoshida of Security Professionals Network Inc.
CVE-2022-25969: Tomohisa Hasegawa
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 8.8 (High) [IPA Score]
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Changed
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS V2 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
  • Access Vector: Local
  • Access Complexity: Low
  • Authentication: Single Instance
  • Confidentiality Impact: Complete
  • Integrity Impact: Complete
  • Availability Impact: Complete
The above CVSS base scores have been assigned for CVE-2022-25949


CVSS V3 Severity:
Base Metrics: 7.8 (High) [IPA Score]
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS V2 Severity:
Base Metrics: 6.8 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2022-26081, CVE-2022-25969, CVE-2022-26511
Affected Products


KINGSOFT, INC.
  • KINGSOFT Internet Security 9 Plus (Reported for Version 2010.06.23.247)
  • Installer of WPS Office (Reported for Version 10.8.0.5745 and Version 10.8.0.6186)
  • WPS Presentation (Reported for Version 11.8.0.5745)

Impact

* A user who can log in to the system where the affected product is installed may obtain the administrative privilege. As a result, arbitrary code may be executed in kernel mode - CVE-2022-25949
* Arbitrary code may be executed with the privilege of the user invoking the installer - CVE-2022-26081, CVE-2022-25969
* Arbitrary code may be executed with the privilege of the running program - CVE-2022-26511
Solution

[Stop using the products and Switch to alternative products]
The developer states that the affected products are no longer supported, and recommends to use alternative unaffected products listed below.

CVE-2022-25949
* KINGSOFT Internet Security20 11.1.6.121416.1905 or later versions

CVE-2022-26081, CVE-2022-25969
* WPS Office2 for Windows 11.82.8498 or later versions

CVE-2022-26511
* WPS Office 2 for Windows Premium Presentation 11.82.8498 or later versions

For more information, refer to the information provided by the developer.
Vendor Information

KINGSOFT, INC.
CWE (What is CWE?)

  1. Buffer Errors(CWE-119) [IPA Evaluation]
  2. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2022-25949
  2. CVE-2022-26081
  3. CVE-2022-25969
  4. CVE-2022-26511
References

  1. JVN : JVNTA#91240916
  2. JVN : JVN#21234459
  3. National Vulnerability Database (NVD) : CVE-2022-25949
  4. National Vulnerability Database (NVD) : CVE-2022-25969
  5. National Vulnerability Database (NVD) : CVE-2022-26081
  6. National Vulnerability Database (NVD) : CVE-2022-26511
Revision History

  • [2022/03/16]
      Web page was published