CVE-2021-35448
Summary
| CVE | CVE-2021-35448 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-24 20:15:00 UTC |
| Updated | 2022-03-29 19:36:00 UTC |
| Description | Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Remotemouse | Emote Interactive Studio | 3.008 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2021-35448 | MISC | leobreaker1411.github.io | |
| Remote Mouse - Local Privilege Escalation | MISC | deathflash.ml | |
| Remote Mouse GUI 3.008 - Local Privilege Escalation - Windows local Exploit | MISC | www.exploit-db.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.