Show plain JSON{"id": "CVE-2018-6400", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.6, "accessVector": "LOCAL", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 3.9, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 1.8}]}, "published": "2018-03-12T21:29:00.953", "references": [{"url": "http://seclists.org/fulldisclosure/2018/Mar/27", "tags": ["Mailing List", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "http://seclists.org/fulldisclosure/2018/Mar/27", "tags": ["Mailing List", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "NVD-CWE-noinfo"}]}], "descriptions": [{"lang": "en", "value": "Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\\\.\\pipe\\WPSCloudSvr\\WpsCloudSvr -- an \"insecurely created named pipe.\" Ensures full access to Everyone users group."}, {"lang": "es", "value": "Kingsoft WPS Office Free 10.2.0.5978 permite que usuarios locales obtengan privilegios o provoquen una denegaci\u00f3n de servicio (DoS) suplantando todas las tuber\u00edas mediante el uso de \\\\.\\pipe\\WPSCloudSvr\\WpsCloudSvr, una \"tuber\u00eda nombrada creada de forma no segura\". Garantiza el acceso total al grupo de usuarios Everyone."}], "lastModified": "2024-11-21T04:10:38.390", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:kingsoftstore:wps_office_free:10.2.0.5978:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "746A4F09-2A9C-47F7-BEF1-CF1990754D26"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}