Unrated severityNVD Advisory· Published May 12, 2022· Updated Apr 15, 2025
CVE-2021-40399
CVE-2021-40399
Description
An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.
Affected products
1- Range: 11.2.0.10351
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security.wps.cn/notices/28mitrex_refsource_CONFIRM
- talosintelligence.com/vulnerability_reports/TALOS-2021-1412mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.