Emote Interactive Remote Mouse 3.008 for Windows contains a vulnerability in its Image Transfer Folder feature, which allows an attacker to navigate to and execute arbitrary programs, such as cmd.exe, with Administrator privileges. The application binds to local ports to listen for incoming connections, which can be leveraged by an attacker to gain elevated code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a working Python exploit for CVE-2021-35448 against the Remote Mouse / WiFi Mouse application, plus a bundled copy of powercat.ps1 used as a post-exploitation reverse-shell payload. The main entry point is RemoteMouse-3.008-RCE.py. It connects to the target over TCP/1978, abuses the Remote Mouse protocol to open cmd.exe on the victim, then simulates keystrokes to type and execute either an arbitrary command or a generated PowerShell one-liner. In reverse-shell mode, the script starts a local HTTP server and serves powercat.ps1 so the victim can download it with System.Net.WebClient and call back to the attacker using powercat -c <ip> -p <port> -e powershell. The exploit is operational rather than just a PoC because it includes a usable payload path and automation for staging the reverse shell. Repository structure is minimal: README.md documents usage and prerequisites, RemoteMouse-3.008-RCE.py performs exploitation and staging, and powercat.ps1 provides the reverse-shell/network utility functionality. No detection logic is present; the repository is clearly intended for exploitation and command execution on vulnerable Windows hosts running the Remote Mouse service.
Repository contains a small standalone Python exploit and a bundled PowerShell helper payload. The main file, CVE-2021-35448.py, targets CVE-2021-35448 in Remote Mouse / WiFi Mouse by connecting to the target over TCP/1978 and sending protocol-specific hex-encoded keystroke packets. The exploit first issues an 'openfile' command for /C/Windows/System32/cmd.exe, then types either an operator-supplied command or a generated PowerShell stager, and finally sends an Enter key event to execute it. This provides remote command execution via simulated keyboard input. The script supports two modes: direct command execution with -p, and reverse-shell staging with -r plus -l. In reverse mode it starts a local Python HTTP server using SimpleHTTPRequestHandler, serves powercat.ps1, and generates a PowerShell one-liner that downloads the script with System.Net.WebClient.DownloadString and invokes powercat to connect back to the attacker with a PowerShell shell. That makes the exploit operational rather than a simple PoC. Repository structure is minimal: README.md documents usage and prerequisites; CVE-2021-35448.py is the actual exploit entry point; powercat.ps1 is a third-party post-exploitation utility used only for reverse-shell delivery. The bundled powercat script is not the vulnerability trigger itself, but it materially extends capability by providing a reusable reverse shell and other networking features. Overall purpose: exploit unauthenticated Remote Mouse command injection/RCE on Windows systems and optionally establish an interactive reverse shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.