CVE-2018-3638 describes an escalation of privilege vulnerability in all versions of the Intel Remote Keyboard and its mobile app. An authorized local attacker can exploit this flaw to execute arbitrary code with elevated privileges. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires local access and low privileges, but can lead to high impacts on confidentiality, integrity, and availability. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, the vulnerability garnered significant media attention and community discussion at the time of its disclosure, with Intel recommending uninstallation of the affected software.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:remote_keyboard_mobile_app:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.