WPS Office for Android versions prior to 17.0.0 are vulnerable to a path traversal issue due to improper sanitization of file names before they are processed in external application interactions. This flaw allows a malicious application to dispatch a specially crafted library file, potentially overwriting an existing native library used by WPS Office. If exploited, this can lead to arbitrary command execution with the privileges of the WPS Office application.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) Android application exploiting a 'Dirty Stream' vulnerability in MI File Explorer V1-210567. The exploit demonstrates the ability to write an arbitrary file ('pwned.txt') into the private shared_prefs directory of the MI File Explorer app, which should not be accessible to third-party apps. The exploit is implemented as an Android app with a MainActivity that, when triggered, sends a crafted intent to the MI File Explorer's CopyFileActivity, leveraging a custom ContentProvider to serve the malicious file. The core exploit logic is in 'MainActivity.java' and 'MyContentProvider.java'. The repository includes standard Android project files, build scripts, and resources. The attack vector is local, requiring the exploit app to be installed and executed on the same device as the vulnerable MI File Explorer app. No network endpoints are involved. The exploit does not provide a reverse shell or remote access, but demonstrates unauthorized file write, which could be leveraged for further attacks if extended. The repository is structured as a typical Android Studio project, with the exploit logic clearly separated in the app module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.