Impact
Remote Keyboard Desktop 1.0.1 contains a flaw that lets an attacker execute arbitrary system commands without authentication. The deficiency lies in an exported function of rundll32.exe that can be invoked remotely, granting an attacker full control over the affected Windows machine and compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Remotecontrolio Remote Keyboard Desktop version 1.0.1 running on Windows. No other versions or platforms are mentioned.
Risk and Exploitability
The CVSS score of 8.9 indicates a high severity. The EPSS score is less than 1%, indicating that exploitation attempts are currently very rare. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the vulnerable export without credentials, making remote code execution possible from any network that can reach the target.
OpenCVE Enrichment