CVE-2018-3645 describes an escalation of privilege vulnerability in all versions of the Intel Remote Keyboard and its mobile application, allowing a local attacker to inject keystrokes into other remote keyboard sessions. This vulnerability carries a CVSS v3 score of 7.8 (High), indicating a low attack complexity with high impacts on confidentiality, integrity, and availability if exploited. Despite its severity, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. However, the vulnerability has garnered significant community discussion and media coverage, with Intel recommending uninstallation of the affected application.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:remote_keyboard_mobile_app:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.