CVE-2018-6400 is a local privilege escalation vulnerability in WPS Office products, originally reported in Kingsoft WPS Office Free 10.2.0.5978 and later confirmed to remain in multiple WPS Co., Ltd. products. The flaw is caused by insufficient access control on an internally used Windows named pipe, including \.\pipe\WPSCloudSvr\WpsCloudSvr, used for inter-process communication with a background service. The named pipe is created with overly permissive access controls, effectively allowing access by low-privileged local users. By connecting to and impersonating or otherwise abusing requests sent through the improperly protected pipe, a non-administrative local user can send crafted requests to the privileged background service and cause arbitrary program execution under SYSTEM. The issue has been described as an insecurely created named pipe and mapped in the provided sources to CWE-749.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege escalation vulnerability in certain WPS Office-related products where improper access controls on a named pipe used by a background service allow a non-administrative local user to execute arbitrary programs with SYSTEM privileges.
A local privilege escalation vulnerability in WPS Office caused by insufficient access control on internally used named pipes, allowing a non-administrative user to execute arbitrary programs with SYSTEM privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.