CVE-2022-3365

CRITICAL

Remote Mouse Server <4.110 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-3365. PoCs published by h00die, 0RPHON, H4rk3nz0, including Metasploit module exploits/windows/misc/remote_mouse_rce.

AI-analyzed exploit summary This Metasploit module exploits CVE-2022-3365 in Remote Mouse Server by Emote Interactive (versions < 4.200) to achieve remote code execution. It leverages the protocol's key simulation feature to open a command prompt and execute a payload via certutil.exe.

Description

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.

Exploits (1)

metasploit WORKING POC NORMAL
by h00die, 0RPHON, H4rk3nz0 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/remote_mouse_rce.rb

This Metasploit module exploits CVE-2022-3365 in Remote Mouse Server by Emote Interactive (versions < 4.200) to achieve remote code execution. It leverages the protocol's key simulation feature to open a command prompt and execute a payload via certutil.exe.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Remote Mouse Server < 4.200
No auth needed
Prerequisites: Target must be running Remote Mouse Server without a password (default configuration) · Network access to TCP port 1978
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0199
EPSS Percentile 78.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-327
Status published
Products (1)
Emote Interactive/Remote Mouse Server < 4.110
Published Jan 28, 2025
Tracked Since Feb 18, 2026