Impact
Deskflow is a keyboard and mouse sharing application that runs its daemon with SYSTEM privileges. In versions 1.20.0, 1.26.0.134 and earlier the daemon exposes an IPC named pipe that is world‑accessible. Because the daemon accepts privileged commands without authentication, any local unprivileged user can interact with that pipe and cause the daemon to execute arbitrary commands as SYSTEM. This flaw permits local privilege escalation and compromise of the host with full administrative rights.
Affected Systems
The vulnerability affects the Deskflow application by Deskflow:deskflow. Versions 1.20.0, 1.26.0.134, and all earlier releases are impacted. Both the stable 1.20.0 release and the continuous 1.26.0.134 prerelease series contain the flaw.
Risk and Exploitability
With a CVSS score of 7.8 the flaw is considered high severity. The EPSS score of less than 1% indicates a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local unprivileged user on the same machine; the attacker would send a crafted request to the world‑accessible named pipe to trigger privileged commands. No network exposure is required, and no special privileges are needed beyond local user access. The attack vector is local, and the critical weakness lies in the lack of authentication and authorization for the IPC interface.
OpenCVE Enrichment