The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components.
As older versions of WPS Office did not validate the update server's certificate, an Adversary-In-The-Middle attack was possible allowing updates to be hijacked.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Mar 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components. As older versions of WPS Office did not validate the update server's certificate, an Adversary-In-The-Middle attack was possible allowing updates to be hijacked. | |
| Title | Use of a weak cryptographic key in the signature verification process in WPS Office | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ESET
Published: 2025-03-27T14:29:22.907Z
Updated: 2025-03-27T15:15:56.127Z
Reserved: 2025-03-19T07:49:48.800Z
Link: CVE-2025-2516
Updated: 2025-03-27T15:15:18.784Z
Status : Awaiting Analysis
Published: 2025-03-27T15:16:01.280
Modified: 2025-03-27T16:45:12.210
Link: CVE-2025-2516
No data.
ReportizFlow