CVE-2024-13187

CVSS 2.0 Score 4.3 of 10 (medium)

Details

Published Jan 8, 2025
CWE ID 94
CWE ID 74

Summary

CVE-2024-13187 is a newly disclosed critical vulnerability affecting Kingsoft WPS Office 6.14.0 on macOS. The issue lies within the TCC Handler component, and its exploitation allows for code injection. An attacker can execute this vulnerability on the local host, making it a significant threat. Although the vendor was informed of the disclosure, they have yet to respond or provide a patch. Public exploits for this vulnerability are currently available and may be used maliciously.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share