CVE-2018-6400
Description
Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecurely created named pipe." Ensures full access to Everyone users group.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
WPS Office's insecurely created named pipe allows local non-administrative users to gain SYSTEM privileges or cause denial of service.
Vulnerability
Kingsoft WPS Office Free 10.2.0.5978 (and other affected versions including WPS Office2 2020/2025 editions, WPS Cloud, WPS Cloud Pro, and KINGSOFT PDF Pro up to version 11.2.0.10715/10716) creates a named pipe at \\.\pipe\WPSCloudSvr\WpsCloudSvr with a NULL DACL, granting full access to the Everyone group. This improper access restriction (CWE-749) allows any local user to interact with the pipe without proper security checks [1][3].
Exploitation
An attacker with local, non-administrative access can connect to the named pipe and impersonate the pipe server or client. By sending crafted requests, the attacker can execute arbitrary commands in the context of the SYSTEM-privileged service that owns the pipe. No user interaction or additional authentication is required beyond the ability to run a local process [1][3].
Impact
Successful exploitation allows the attacker to execute arbitrary programs with SYSTEM privilege, leading to full compromise of the affected Windows system. This includes the ability to read, modify, or delete any data, install persistent malware, or cause a denial of service [1][3].
Mitigation
Users should update to the latest version provided by the vendor. For personal products, update to WPS Office2 (2025 edition) version 11.2.0.10721 or later; for other affected products, follow the vendor's update instructions available at [2]. No workaround other than updating is documented. Older versions (e.g., 10.2.0.5978) remain vulnerable and should be upgraded immediately [1][3].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: = 10.2.0.5978
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
3- seclists.org/fulldisclosure/2018/Mar/27nvdMailing ListThird Party Advisory
- jvn.jp/en/jp/JVN14434132/nvd
- www.wps365.jp/notices/4nvd
News mentions
0No linked articles in our index yet.