Description
Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.
Problem types
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
1.0.1
Credits
Chokri Hammedi, github.com/blue0x1
References
www.exploit-db.com/exploits/52299
www.exploit-db.com/exploits/52299 (ExploitDB-52299)
remotecontrolio.web.app/ (Vendor Homepage)
apps.microsoft.com/...8v5sc9m?hl=neutral&gl=US&ocid=pdpshare (Software Link)
www.vulncheck.com/...d-desktop-101-remote-code-execution-rce