Hackers have exploited a WPS Office zero-day to spread dangerous malware

Popular workplace productivity software WPS Office contained a vulnerability that could allow attackers to install backdoors on targets’ endpoints, experts claim.

Cybersecurity researchers at ESET discovered that WPS Office was vulnerable to an improper path validation error, tracked as CVE-2024-7262. It has a severity rating of 9.3 (critical) and affects multiple versions (from 12.2. 0. 13110 to 12.1. 0. 16412). The first patch to fix the issue was released in March 2024, but some threat actors reportedly exploited it a month earlier.