logo

Analysis of two arbitrary code execution vulnerabilities affecting WPS Office

ID: 3742769d-8306-5f71-bdfd-c8a4ed64ad88

STIX ID: report--3742769d-8306-5f71-bdfd-c8a4ed64ad88

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2024-08-28

Date Updated: 2026-05-01

...
...

ESET discovered and analyzed in-the-wild exploitation of a WPS Office for Windows code-execution vulnerability (CVE-2024-7262) used by APT-C-60 to deliver a custom backdoor (SpyGlace/TaskControler.dll), and uncovered a second related vulnerability (CVE-2024-7263) after inspecting the vendor patch; the report details the ksoqing protocol abuse, MHTML-driven remote DLL download and load-chain, affected versions, timeline, IoCs and urges urgent updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.