CVE-2018-3641 describes an escalation of privilege vulnerability in all versions of the Intel Remote Keyboard and its mobile app, allowing a network attacker to inject keystrokes as a local user. This critical vulnerability has a CVSS score of 9.8, indicating a severe impact with high confidentiality, integrity, and availability compromise, requiring no user interaction or complex attack vectors. While there is no known public exploit code or active exploitation, the vulnerability has garnered significant community discussion and media coverage, with Intel advising users to uninstall the affected application.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:remote_keyboard_mobile_app:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.