CVE-2022-3365

CRITICAL

Remote Mouse Server <4.110 - Command Injection

Title source: llm

Description

Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct's custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.

Exploits (1)

metasploit WORKING POC NORMAL
by h00die, 0RPHON, H4rk3nz0 · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/remote_mouse_rce.rb

Scores

CVSS v3 9.8
EPSS 0.5260
EPSS Percentile 98.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-327
Status published
Products (1)
Emote Interactive/Remote Mouse Server < 4.110
Published Jan 28, 2025
Tracked Since Feb 18, 2026