CVE-2022-25943 Vulnerability Details

  /     /     /  

CVE-2022-25943 Metadata Quick Info

CVE Published: 09/03/2022 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: jpcert | Vendor: WPS Office Software | Product: WPS Office for Windows
Status : PUBLISHED

CVE-2022-25943 Description

The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-276
CWE Name: CWE-276: Incorrect Default Permissions
Source: WPS Office Software

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).