[Japanese]
|
JVNDB-2022-000021
|
Multiple vulnerabilities in KINGSOFT "WPS Office" and "KINGSOFT Internet Security"
|
"WPS Office" and "KINGSOFT Internet Security" provided by KINGSOFT JAPAN, INC. contain multiple vulnerabilities listed below.
* Stack-based buffer overflow (CWE-121) - CVE-2022-25949
* Insecurely loading Dynamic Link Libraries (CWE-427) - CVE-2022-26081, CVE-2022-25969, CVE-2022-26511
These vulnerabilities are reported by the following reporters, and
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVE-2022-26949: Satoshi Tanda
CVE-2022-26081, CVE-2022-26511: Eiji James Yoshida of Security Professionals Network Inc.
CVE-2022-25969: Tomohisa Hasegawa
|
CVSS V3 Severity: Base Metrics 8.8 (High) [IPA Score]
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Changed
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
CVSS V2 Severity: Base Metrics 6.8 (Medium) [IPA Score]
- Access Vector: Local
- Access Complexity: Low
- Authentication: Single Instance
- Confidentiality Impact: Complete
- Integrity Impact: Complete
- Availability Impact: Complete
The above CVSS base scores have been assigned for CVE-2022-25949
|
CVSS V3 Severity:
Base Metrics:
7.8 (High) [IPA Score]
-
Attack Vector: Local
-
Attack Complexity: Low
-
Privileges Required: None
-
User Interaction: Required
-
Scope: Unchanged
-
Confidentiality Impact: High
-
Integrity Impact: High
-
Availability Impact: High
CVSS V2 Severity:Base Metrics:
6.8 (Medium)
[IPA Score]
-
Access Vector: Network
-
Access Complexity: Medium
-
Authentication: None
-
Confidentiality Impact: Partial
-
Integrity Impact: Partial
-
Availability Impact: Partial
The above CVSS base scores have been assigned for CVE-2022-26081, CVE-2022-25969, CVE-2022-26511
|
|
KINGSOFT, INC.
- KINGSOFT Internet Security 9 Plus (Reported for Version 2010.06.23.247)
- Installer of WPS Office (Reported for Version 10.8.0.5745 and Version 10.8.0.6186)
- WPS Presentation (Reported for Version 11.8.0.5745)
|
|
* A user who can log in to the system where the affected product is installed may obtain the administrative privilege. As a result, arbitrary code may be executed in kernel mode - CVE-2022-25949
* Arbitrary code may be executed with the privilege of the user invoking the installer - CVE-2022-26081, CVE-2022-25969
* Arbitrary code may be executed with the privilege of the running program - CVE-2022-26511
|
[Stop using the products and Switch to alternative products]
The developer states that the affected products are no longer supported, and recommends to use alternative unaffected products listed below.
CVE-2022-25949
* KINGSOFT Internet Security20 11.1.6.121416.1905 or later versions
CVE-2022-26081, CVE-2022-25969
* WPS Office2 for Windows 11.82.8498 or later versions
CVE-2022-26511
* WPS Office 2 for Windows Premium Presentation 11.82.8498 or later versions
For more information, refer to the information provided by the developer.
|
KINGSOFT, INC.
|
- Buffer Errors(CWE-119) [IPA Evaluation]
- No Mapping(CWE-Other) [IPA Evaluation]
|
- CVE-2022-25949
- CVE-2022-26081
- CVE-2022-25969
- CVE-2022-26511
|
- JVN : JVNTA#91240916
- JVN : JVN#21234459
- National Vulnerability Database (NVD) : CVE-2022-25949
- National Vulnerability Database (NVD) : CVE-2022-25969
- National Vulnerability Database (NVD) : CVE-2022-26081
- National Vulnerability Database (NVD) : CVE-2022-26511
|
- [2022/03/16]
Web page was published
|