The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components.
As older versions of WPS Office did not validate the update server's certificate, an Adversary-In-The-Middle attack was possible allowing updates to be hijacked.
CVSS
No CVSS.
References
Configurations
No configuration.
History
27 Mar 2025, 15:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-27 15:16
Updated : 2025-03-27 16:45
NVD link : CVE-2025-2516
Mitre link : CVE-2025-2516
CVE.ORG link : CVE-2025-2516
JSON object : View
Products Affected
No product.
CWE
CWE-326
Inadequate Encryption Strength