CVE-2018-6390 describes a denial-of-service vulnerability in Kingsoft WPS Office versions 10.1.0.7106 and 10.2.0.5978. The flaw, located in the WStr::assign function within kso.dll, stems from insufficient validation of source memory block sizes before a memory copy operation. This allows remote attackers to trigger an access violation and application crash by presenting a specially crafted web page, office document, or RTF file. Rated with a CVSS score of 6.5 (Medium), this vulnerability requires user interaction (UI:R) but can be exploited over a network (AV:N) with low attack complexity (AC:L), leading to high availability impact (A:H). Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.1.0.7106CPE matchmatch criteria | cpe:2.3:a:wps:wps_office:10.1.0.7106:*:*:*:*:*:*:* | ||
10.2.0.5978CPE matchmatch criteria | cpe:2.3:a:wps:wps_office:10.2.0.5978:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.