CVE-2022-3365 – Emote Interactive Remote Mouse Server OS Command Injection Vulnerability

The following table lists the changes that have been made to the
CVE-2022-3365 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 28, 2025

    Action Type Old Value New Value
    Added Description Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the user does not set a password, the Remote Mouse Server by Emote Interactive can be abused by attackers to inject OS commands over theproduct’s custom control protocol. A Metasploit module was written and tested against version 4.110, the current version when this CVE was reserved.
    Added CWE CWE-327
    Added Reference https://github.com/rapid7/metasploit-framework/pull/17067
Share the Post:

Related Posts