Published:2026/05/14  Last Updated:2026/05/14

JVN#14434132
WPS Office improper access restriction to its named pipe

Overview

WPS Office provided by WPS SOFTWARE PTE. LTD. fails to properly restrict access to its named pipe.

Products Affected

  • WPS Office2 (2020 edition) Ver.11.2.0.10707 and earlier
  • WPS Office2 (2025 edition) Ver.11.2.0.10715 and earlier
  • WPS Cloud Ver.11.2.0.10715 and earlier
  • WPS Cloud Pro Ver.11.2.0.10716 and earlier
  • KINGSOFT PDF Pro Ver.11.2.0.10715 and earlier

Description

WPS Office provided by WPS SOFTWARE PTE. LTD. contains a service program running background and providing certain functionalities to the other programs. This service program uses a named pipe to communicate with the other programs.
The named pipe above is not properly protected and any non-administrative user can access it.

  • Exposed dangerous method or function (CWE-749)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.5
    • CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 7.8
    • CVE-2018-6400

Impact

A non-administrative user may execute arbitrary programs with SYSTEM privilege.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

MASAHIRO IIDA of LAC Co., Ltd. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000074