The installer for WPS Office for Windows versions prior to v11.2.0.10258 does not properly configure the Access Control List (ACL) for the directory where the service program is installed. This misconfiguration can allow unauthorized users to modify or replace files within the service directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a local privilege escalation exploit targeting Kingsoft WPS Office (CVE-2022-25943) on Windows. The exploit leverages a weak ACL configuration on the directory 'C:\ProgramData\kingsoft\office6\', allowing a low-privileged user to plant a malicious DLL (CRYPTSP.dll). The main exploit steps are: 1. The attacker places a crafted DLL (src/dll.cpp) in the vulnerable directory. 2. The exploit binary (src/exploit.cpp) copies the DLL, restarts the 'wpscloudsvr' service (which runs as SYSTEM), causing it to load the attacker's DLL. 3. The DLL, when loaded, enables the Administrator account and sets its password to 'p@@wned'. 4. The exploit then logs in as Administrator and runs a secondary binary (src/nt-sys.cpp) to steal the winlogon token and spawn a SYSTEM shell. The repository is structured as follows: - 'src/dll.cpp': The malicious DLL payload. - 'src/exploit.cpp': The main exploit logic for DLL planting, service restart, and privilege escalation. - 'src/nt-sys.cpp': Utility for token theft and SYSTEM shell spawning. No network endpoints are involved; the attack is purely local. The exploit is operational and provides a working privilege escalation chain from a low-privileged user to SYSTEM on vulnerable WPS Office installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.