Analysis of two arbitrary code execution vulnerabilities affecting WPS Office
ESET researchers discovered a code execution vulnerability in WPS Office for Windows (CVE-2024-7262), as it was being exploited by APT-C-60, a South Korea-aligned cyberespionage group. Upon analyzing the root cause, we subsequently discovered another way to exploit the faulty code (CVE-2924-7263). Following a coordinated disclosure process, both vulnerabilities are now patched – in this blogpost, we provide technical details. Key points of the blogpost: APT-C-60 weaponized a code execution vulnerability in WPS Office for Windows…
Read More
