VYPR
High severity7.8NVD Advisory· Published Mar 12, 2018· Updated May 14, 2026

CVE-2018-6400

CVE-2018-6400

Description

Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecurely created named pipe." Ensures full access to Everyone users group.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WPS Office's insecurely created named pipe allows local non-administrative users to gain SYSTEM privileges or cause denial of service.

Vulnerability

Kingsoft WPS Office Free 10.2.0.5978 (and other affected versions including WPS Office2 2020/2025 editions, WPS Cloud, WPS Cloud Pro, and KINGSOFT PDF Pro up to version 11.2.0.10715/10716) creates a named pipe at \\.\pipe\WPSCloudSvr\WpsCloudSvr with a NULL DACL, granting full access to the Everyone group. This improper access restriction (CWE-749) allows any local user to interact with the pipe without proper security checks [1][3].

Exploitation

An attacker with local, non-administrative access can connect to the named pipe and impersonate the pipe server or client. By sending crafted requests, the attacker can execute arbitrary commands in the context of the SYSTEM-privileged service that owns the pipe. No user interaction or additional authentication is required beyond the ability to run a local process [1][3].

Impact

Successful exploitation allows the attacker to execute arbitrary programs with SYSTEM privilege, leading to full compromise of the affected Windows system. This includes the ability to read, modify, or delete any data, install persistent malware, or cause a denial of service [1][3].

Mitigation

Users should update to the latest version provided by the vendor. For personal products, update to WPS Office2 (2025 edition) version 11.2.0.10721 or later; for other affected products, follow the vendor's update instructions available at [2]. No workaround other than updating is documented. Older versions (e.g., 10.2.0.5978) remain vulnerable and should be upgraded immediately [1][3].

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.