Vulnerabilities > CVE-2018-6400 - Unspecified vulnerability in Kingsoftstore WPS Office Free 10.2.0.5978

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
kingsoftstore

Summary

Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecurely created named pipe." Ensures full access to Everyone users group.

Vulnerable Configurations

Part Description Count
Application
Kingsoftstore
1

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/146709/TSI-ADV162018.txt
idPACKETSTORM:146709
last seen2018-03-23
published2018-03-08
reporterFelipe Xavier Oliveira
sourcehttps://packetstormsecurity.com/files/146709/WPS-Free-Office-10.2.0.5978-NULL-DACL-Grants-Full-Access.html
titleWPS Free Office 10.2.0.5978 NULL DACL Grants Full Access