7.8
CVSSv3

CVE-2018-6400

Published: 12/03/2018 Updated: 03/10/2019
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecurely created named pipe." Ensures full access to Everyone users group.

Vulnerable Product Search on Vulmon Subscribe to Product

kingsoftstore wps office free 10.2.0.5978

Exploits

WPS Free Office version 10205978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through the use of an insecurely created named pipe ...