RemotemouseCVEs & Vulnerabilities

8 CVEs affecting Remotemouse products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

emote remote mouse 6remote mouse 2emote interactive studio 1
CVE-2021-47792HIGH

Remote Mouse 4.002 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the RemoteMouseService to inject malicious executables and gain administrative access.

16 Jan 2026
7.8
CVSS
CVE-2021-35448HIGHpoc

Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using the Image Transfer Folder feature to navigate to cmd.exe. It binds to local ports to listen for incoming connections.

24 Jun 2021
7.8
CVSS
CVE-2021-27574HIGH

An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.

7 May 2021
8.1
CVSS
CVE-2021-27573CRITICAL

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Remote unauthenticated users can execute arbitrary code via crafted UDP packets with no prior authorization or authentication.

7 May 2021
9.8
CVSS
CVE-2021-27572HIGH

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Authentication Bypass can occur via Packet Replay. Remote unauthenticated users can execute arbitrary code via crafted UDP packets even when passwords are set.

7 May 2021
8.1
CVSS
CVE-2021-27571MEDIUM

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can retrieve recently used and running applications, their icons, and their file paths. This information is sent in cleartext and is not protected by any authentication logic.

7 May 2021
5.3
CVSS
CVE-2021-27570MEDIUM

An issue was discovered in Emote Remote Mouse through 3.015. Attackers can close any running process by sending the process name in a specially crafted packet. This information is sent in cleartext and is not protected by any authentication logic.

7 May 2021
5.3
CVSS
CVE-2021-27569MEDIUM

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the process name in a crafted packet. This information is sent in cleartext and is not protected by any authentication logic.

7 May 2021
5.3
CVSS
← PrevPage 1 / 1Next →