VYPR
Unrated severityNVD Advisory· Published Jun 13, 2023· Updated Jan 3, 2025

CVE-2023-32548

CVE-2023-32548

Description

OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

WPS Office 10.8.0.6186 allows OS command injection via man-in-the-middle attack, leading to arbitrary command execution.

Vulnerability

WPS Office version 10.8.0.6186 contains an OS command injection vulnerability (CWE-78). The vulnerability exists in the update mechanism, where the product communicates with an update server. An attacker can exploit this by conducting a man-in-the-middle attack or by modifying the registry or configuration files to redirect the update server to a malicious server [1][2].

Exploitation

An attacker must be able to perform a man-in-the-middle attack on the network traffic between the vulnerable WPS Office installation and its legitimate update server, or have write access to the registry or configuration files to change the server address. Once the connection is redirected to a malicious server, the attacker sends a specially crafted response that triggers OS command injection [1]. No user interaction beyond running the update mechanism is required.

Impact

Successful exploitation allows the attacker to execute arbitrary OS commands on the system where WPS Office is installed, with the privileges of the user running the application. This can lead to full compromise of confidentiality, integrity, and availability [1].

Mitigation

No patch is available for WPS Office version 10.8.0.6186 as it is an end-of-life product. The vendor recommends users to stop using "WPS Office" and switch to "WPS Office2", which is not affected by this vulnerability [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.