CVE-2022-3365
CRITICALRemote Mouse Server <4.110 - Command Injection
Title source: llmDescription
Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.
Exploits (1)
metasploit
WORKING POC
NORMAL
by h00die, 0RPHON, H4rk3nz0 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/remote_mouse_rce.rb
Scores
CVSS v3
9.8
EPSS
0.5260
EPSS Percentile
98.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-327
Status
published
Products (1)
Emote Interactive/Remote Mouse Server
< 4.110
Published
Jan 28, 2025
Tracked Since
Feb 18, 2026