We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-2516

Use of a weak cryptographic key in the signature verification process in WPS Office



Description

The use of a weak cryptographic key pair in the signature verification process in WPS Office (Kingsoft) on Windows allows an attacker who successfully recovered the private key to sign components. As older versions of WPS Office did not validate the update server's certificate, an Adversary-In-The-Middle attack was possible allowing updates to be hijacked.

Reserved 2025-03-19 | Published 2025-03-27 | Updated 2025-03-27 | Assigner ESET


CRITICAL: 9.5CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/U:Amber

Problem types

CWE-326 Inadequate Encryption Strength

Product status

Default status
unknown

12.1.0.18276
unknown

References

www.welivesecurity.com/...abled-implant-evolving-since-2005/

cve.org (CVE-2025-2516)

nvd.nist.gov (CVE-2025-2516)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-2516

Support options

Helpdesk Chat, Email, Knowledgebase