Analysis of two arbitrary code execution vulnerabilities affecting WPS Office
ID: 3742769d-8306-5f71-bdfd-c8a4ed64ad88
STIX ID: report--3742769d-8306-5f71-bdfd-c8a4ed64ad88
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET discovered and analyzed in-the-wild exploitation of a WPS Office for Windows code-execution vulnerability (CVE-2024-7262) used by APT-C-60 to deliver a custom backdoor (SpyGlace/TaskControler.dll), and uncovered a second related vulnerability (CVE-2024-7263) after inspecting the vendor patch; the report details the ksoqing protocol abuse, MHTML-driven remote DLL download and load-chain, affected versions, timeline, IoCs and urges urgent updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
