Vulnerability Description
Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecurely created named pipe." Ensures full access to Everyone users group.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kingsoftstore | Wps Office Free | 10.2.0.5978 |
References
- http://seclists.org/fulldisclosure/2018/Mar/27Mailing ListThird Party Advisory
- https://jvn.jp/en/jp/JVN14434132/
- https://www.wps365.jp/notices/4
- http://seclists.org/fulldisclosure/2018/Mar/27Mailing ListThird Party Advisory
FAQ
What is CVE-2018-6400?
CVE-2018-6400 is a vulnerability with a CVSS score of 7.8 (HIGH). Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecure...
How severe is CVE-2018-6400?
CVE-2018-6400 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-6400?
Check the references section above for vendor advisories and patch information. Affected products include: Kingsoftstore Wps Office Free.