ET EXPLOIT Kingsoft WPS Office ksoqing URI Handler Remote Code Execution Attempt (CVE-2024-7262)

7.0.35.0SID: 2071563Rev: 1Enabled2 views
Sourceet/open
Fileemerging-exploit.rules
CreatedAugust 18, 2026
UpdatedAugust 18, 2026
Classificationtrojan-activity
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT Kingsoft WPS Office ksoqing URI Handler Remote Code Execution Attempt (CVE-2024-7262)"; flow:established,to_client; file.data; content:"ksoqing|3a 2f 2f|"; fast_pattern; content:"type|3d|ksolaunch"; content:"cmd|3d|"; content:"launchname|3d|promcefpluginhost.exe"; reference:url,www.welivesecurity.com/en/eset-research/analysis-of-two-arbitrary-code-execution-vulnerabilities-affecting-wps-office/; reference:cve,2024-7262; classtype:trojan-activity; sid:2071563; rev:1; metadata:affected_product WPS_Office, attack_target Client_and_Server, tls_state TLSDecrypt, created_at 2026_08_18, cve CVE_2024_7262, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, updated_at 2026_08_18; target:dest_ip;)

Metadata

affected productWPS_Office
attack targetClient_and_Server
tls stateTLSDecrypt
created at2026_08_18
deploymentInternal
performance impactLow
confidenceHigh
signature severityMajor
tagExploit
updated at2026_08_18

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!