PT-2021-17512 · Unknown · Emote Remote Mouse
Axel Persinger
·
Published
2021-05-07
·
Updated
2022-07-12
·
CVE-2021-27570
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Emote Remote Mouse versions through 3.015
Description
An issue allows attackers to close any running process by sending the process name in a specially crafted packet. The information is sent in cleartext and lacks authentication logic.
Recommendations
For Emote Remote Mouse versions through 3.015, consider restricting access to the process control functionality until a patch is available. As a temporary workaround, implement additional authentication logic to protect against unauthorized process closure.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Emote Remote Mouse