RULE(RULE ID:714903)

Rule General Information
Release Date: 2021-05-08
Rule Name: WPS Office Heap Buffer Overflow Vulnerability (CVE-2020-25291)
Severity:
CVE ID:
Rule Protection Details
Description: GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, Others
Reference: http://zeifan.my/security/rce/heap/2020/09/03/wps-rce-heap.html
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
http://zeifan.my/security/rce/heap/2020/09/03/wps-rce-heap.html