PT-2021-17511 · Unknown · Emote Remote Mouse
Axel Persinger
·
Published
2021-05-07
·
Updated
2022-07-12
·
CVE-2021-27569
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Emote Remote Mouse versions through 4.0.0.0
Description
An issue allows attackers to maximize or minimize the window of a running process by sending the process name in a crafted packet. The information is sent in cleartext and lacks authentication logic.
Recommendations
For versions through 4.0.0.0, consider restricting access to the process name information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emote Remote Mouse