CVE-2024-7262

Kingsoft — Kingsoft WPS Office Path Traversal Vulnerability

CISA KEV · in the CISA KEV catalog since 2024-09-03

What EVULNABLE says

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data
Overdue by 23 monthsCISA KEVActively Exploited

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Patch This Cycle

The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.

The evidence behind it

Published measurements for CVE-2024-7262
MeasureValueSource
CVSS base score 9.3 NVD
FIRST EPSS 0.029 (86.2nd pctl) FIRST
Actively exploited Confirmed CISA KEV
Ransomware campaign use Unknown or none CISA KEV
CISA remediation deadline 2024-09-24 — Overdue by 23 months CISA KEV
Intelligence coverage 75/90 — no pre-patch disclosure data

What CISA says to do

  • While CISA cannot confirm the effectiveness of patches at this time, it is recommended that mitigations be applied per vendor instructions if available. If these instructions cannot be located or if mitigations are unavailable, discontinue the use of the product
  • nvd.nist.gov/…/CVE-2024-7262 ↗

This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.