ET EXPLOIT Kingsoft WPS Office ksoqing URI Handler Remote Code Execution Attempt (CVE-2024-7262)
Sourceet/open
Fileemerging-exploit.rules
CreatedAugust 18, 2026
UpdatedAugust 18, 2026
Classificationtrojan-activity
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Kingsoft WPS Office ksoqing URI Handler Remote Code Execution Attempt (CVE-2024-7262)"; flow:established,to_client ; file.data; content:"ksoqing|3a 2f 2f|"; fast_pattern; content:"type|3d|ksolaunch"; content:"cmd|3d|"; content:"launchname|3d|promcefpluginhost.exe"; reference:url,www.welivesecurity.com/en/eset-research/analysis-of-two-arbitrary-code-execution-vulnerabilities-affecting-wps-office/ ; reference:cve,2024-7262 ; classtype:trojan-activity; sid:2071563; rev:1; metadata:affected_product WPS_Office, attack_target Client_and_Server, tls_state TLSDecrypt, created_at 2026_08_18, cve CVE_2024_7262, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2026_08_18; target:dest_ip;)
References
Metadata
affected productWPS_Office
attack targetClient_and_Server
tls stateTLSDecrypt
created at2026_08_18
deploymentInternal
performance impactLow
confidenceHigh
signature severityMajor
tagExploit
updated at2026_08_18
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!