CVE-2024-7262
Kingsoft — Kingsoft WPS Office Path Traversal Vulnerability
What EVULNABLE says
EVULNABLE Risk · priority
75/100
Urgent
Raised to the floor for a confirmed exploited vulnerability.
Intelligence coverage 75/90 — no pre-patch disclosure data
The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.
The evidence behind it
| Measure | Value | Source |
|---|---|---|
| CVSS base score | 9.3 | NVD |
| FIRST EPSS | 0.029 (86.2nd pctl) | FIRST |
| Actively exploited | Confirmed | CISA KEV |
| Ransomware campaign use | Unknown or none | CISA KEV |
| CISA remediation deadline | 2024-09-24 — Overdue by 23 months | CISA KEV |
What CISA says to do
- While CISA cannot confirm the effectiveness of patches at this time, it is recommended that mitigations be applied per vendor instructions if available. If these instructions cannot be located or if mitigations are unavailable, discontinue the use of the product
- nvd.nist.gov/…/CVE-2024-7262 ↗
The primary records
This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.