Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-25943 — CVE-2022-25943 | Kitploit
Tools/GitHubGitHub/webraybtl/cve-2022-25943
Privilege EscalationVulnerability AnalysisExploitationLearning & EducationBinary Exploitation
GitHubwebraybtl/cve-2022-25943

CVE-2022-25943

CVE-2022-25943

View Repository
663 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-24934

Vulnerability Overview

When installing WPS Office, the service program wpscloudsvr is installed with administrator privileges. This service is configured for manual start, but the access control list (ACL) attributes of the folder where the service program resides are misconfigured. Ordinary Users group members still have read and write permissions to this folder.

Affected Versions

All WPS Office versions earlier than 11.2.0.10258 are affected by this vulnerability.

(The WPS version number is determined by the last group of digits; a larger last group indicates a newer version. 11.1 indicates the personal edition, 11.2 indicates the enterprise edition, and 11.6 and 11.8 indicate customized government/enterprise editions.)

Exploitation Scenario

An ordinary Users group member places a hijacked DLL file in the folder where the service program wpscloudsvr resides, starts the service with ordinary user privileges, and ultimately the DLL is loaded and executed by the service program, achieving local privilege escalation.

(The wpscloudsvr service program itself does not have a DLL hijacking vulnerability; system DLL hijacking vulnerabilities can be used. During testing, on a Win7 6.1.7601 SP1 32-bit system, an exploitable system DLL hijacking vulnerability exists. On a Win10 10.0.18363.592 64-bit system, no exploitable DLL hijacking vulnerability was found.)

Reproduction Environment

Operating System: Win7 SP1.

WPS Office Version: WPS Office 11.2.0.10200.

Tools used: Process Explorer, Process Monitor, CFF Explorer, vs2008.

Analysis tools: Detect It Easy, OD, IDA, Openssl, digital signature copying tool sigthief.py.

Vulnerability Details & Technical Consultation

Image

Disclaimer:

This article is solely for the purpose of technical exchange, learning, and research. It is strictly forbidden to use the techniques described in this article for illegal purposes or destructive actions. The author of this article shall not be held responsible for any consequences arising from such misuse.

Chinese Version:

This disclaimer is intended to clearly state that this article is solely for the purpose of technical exchange, learning, and research, and the use of the techniques mentioned in the article for any illegal purposes or destructive actions is strictly prohibited. The author of this article shall not be held responsible for any consequences resulting from the misuse of the techniques mentioned.

By reading and referring to this article, you must acknowledge and commit that you will not exploit the techniques provided in the article for any illegal activities, infringement of rights of others, or attacks on systems. The author of this article bears no responsibility for any accidents, losses, or damages caused by the use of the techniques mentioned in this article, including but not limited to data loss, property damage, legal liabilities, etc.

The technical information provided in this article is for learning and reference purposes only and does not constitute any form of warranty or guarantee. The author of this article makes no representations or warranties regarding the accuracy, effectiveness, or applicability of the techniques mentioned.

English Version:

This disclaimer is intended to clearly state that this article is solely for the purpose of technical exchange, learning, and research, and the use of the techniques mentioned in the article for any illegal purposes or destructive actions is strictly prohibited. The author of this article shall not be held responsible for any consequences resulting from the misuse of the techniques mentioned.

By reading and referring to this article, you must acknowledge and commit that you will not exploit the techniques provided in the article for any illegal activities, infringement of rights of others, or attacks on systems. The author of this article bears no responsibility for any accidents, losses, or damages caused by the use of the techniques mentioned in this article, including but not limited to data loss, property damage, legal liabilities, etc.

The technical information provided in this article is for learning and reference purposes only and does not constitute any form of warranty or guarantee. The author of this article makes no representations or warranties regarding the accuracy, effectiveness, or applicability of the techniques mentioned.

Download Tool