{"api_version":"1","generated_at":"2026-07-23T11:58:24+00:00","cve":"CVE-2021-35448","urls":{"html":"https://cve.report/CVE-2021-35448","api":"https://cve.report/api/cve/CVE-2021-35448.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-35448","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-35448"},"summary":{"title":"CVE-2021-35448","description":"Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-06-24 20:15:00","updated_at":"2022-03-29 19:36:00"},"problem_types":["CWE-269"],"metrics":[],"references":[{"url":"https://leobreaker1411.github.io/blog/cve-2021-35448","name":"https://leobreaker1411.github.io/blog/cve-2021-35448","refsource":"MISC","tags":[],"title":"CVE-2021-35448","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://deathflash.ml/blog/remote-mouse-lpe","name":"https://deathflash.ml/blog/remote-mouse-lpe","refsource":"MISC","tags":[],"title":"Remote Mouse - Local Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.exploit-db.com/exploits/50047","name":"https://www.exploit-db.com/exploits/50047","refsource":"MISC","tags":[],"title":"Remote Mouse GUI 3.008 - Local Privilege Escalation - Windows local Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-35448","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-35448","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"35448","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"35448","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"remotemouse","cpe5":"emote_interactive_studio","cpe6":"3.008","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-35448","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://deathflash.ml/blog/remote-mouse-lpe","refsource":"MISC","name":"https://deathflash.ml/blog/remote-mouse-lpe"},{"url":"https://www.exploit-db.com/exploits/50047","refsource":"MISC","name":"https://www.exploit-db.com/exploits/50047"},{"refsource":"MISC","name":"https://leobreaker1411.github.io/blog/cve-2021-35448","url":"https://leobreaker1411.github.io/blog/cve-2021-35448"}]}},"nvd":{"publishedDate":"2021-06-24 20:15:00","lastModifiedDate":"2022-03-29 19:36:00","problem_types":["CWE-269"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:remotemouse:emote_interactive_studio:3.008:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"35448","Ordinal":"210940","Title":"CVE-2021-35448","CVE":"CVE-2021-35448","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"35448","Ordinal":"1","NoteData":"Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"35448","Ordinal":"2","NoteData":"2021-06-24","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"35448","Ordinal":"3","NoteData":"2021-12-29","Type":"Other","Title":"Modified"}]}}}