Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-24934 — Technical analysis and proof-of-concept exploit for CVE-2022-24934, a privilege escalation vulnerability in WPS Office's update mechanism allowing arbitrary code execution via registry manipulation. | Kitploit
Tools/GitHubGitHub/webraybtl/cve-2022-24934
Vulnerability AnalysisExploitationBinary AnalysisPapers & ResearchLearning & Education
GitHubwebraybtl/cve-2022-24934

CVE-2022-24934

Technical analysis and proof-of-concept exploit for CVE-2022-24934, a privilege escalation vulnerability in WPS Office's update mechanism allowing arbitrary code execution via registry manipulation.

View Repository
201033 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-24934

Vulnerability Overview

WPS Office's updater wpsupdate.exe reads a custom update server address from the registry HKEY_CURRENT_USER, downloads a custom update program, and executes it, leading to arbitrary code execution.

Affected Versions

WPS Office versions less than or equal to 11.2.0.10382 are vulnerable.

(WPS version numbers: the last group indicates the version; a larger last number means a newer version. 11.1 denotes the personal edition, 11.2 the enterprise edition, 11.6 and 11.8 the government-customized edition.)

Reproduction Environment

Operating system: Win7 sp1.

WPS Office version: WPS 2019 v11.8.2.10229.

Analysis tools: Detect It Easy, OD, IDA, Openssl, Digital signature copying tool sigthief.py.

Technical Consultation

Image invalid

Disclaimer:

This article is solely for the purpose of technical exchange, learning, and research. The use of the techniques mentioned in the article for any illegal purpose or destructive action is strictly prohibited. The author of this article shall not be held responsible for any consequences resulting from the misuse of the techniques mentioned.

Chinese Version:

本免责声明旨在明确指出,本文仅为技术交流、学习和研究之用,不得将文章中的技术用于任何非法目的或破坏行为。发表本文章的作者对于任何非法使用技术或对他人或系统造成的损害概不负责。

阅读和参考本文章时,您必须明确并承诺,不会利用文章中提供的技术来实施非法活动、侵犯他人的权益或对系统进行攻击。任何使用本文中的技术所导致的任何意外、损失或损害,包括但不限于数据损失、财产损失、法律责任等问题,都与发表本文章的作者无关。

本文提供的技术信息仅供学习和参考之用,不构成任何形式的担保或保证。发表本文章的作者不对技术的准确性、有效性或适用性做任何声明或保证。

English Version:

This disclaimer is intended to clearly state that this article is solely for the purpose of technical exchange, learning, and research, and the use of the techniques mentioned in the article for any illegal purposes or destructive actions is strictly prohibited. The author of this article shall not be held responsible for any consequences resulting from the misuse of the techniques mentioned.

By reading and referring to this article, you must acknowledge and commit that you will not exploit the techniques provided in the article for any illegal activities, infringement of rights of others, or attacks on systems. The author of this article bears no responsibility for any accidents, losses, or damages caused by the use of the techniques mentioned in this article, including but not limited to data loss, property damage, legal liabilities, etc.

The technical information provided in this article is for learning and reference purposes only and does not constitute any form of warranty or guarantee. The author of this article makes no representations or warranties regarding the accuracy, effectiveness, or applicability of the techniques mentioned.

Download Tool