Share
## https://sploitus.com/exploit?id=E9377F01-1DC8-5F09-8C67-4597C2FA26A7
# CVE-2021-35448

### Description:

A local privilege escalation vulnerability was discovered in `Remote Mouse 3.008` via it's GUI

### Steps to reproduce:

1. Open Remote Mouse from the system tray
2. Go to "Settings"
3. Click "Change..." in "Image Transfer Folder" section
4. "Save As" prompt will appear
5. Enter "C:\Windows\System32\cmd.exe" in the address bar
6. A new command prompt is spawned with Administrator privileges

### Proof of concept:

![Proof of Concept](PoC.png)

### References:

- [https://leobreaker1411.github.io/blog/cve-2021-35448](https://leobreaker1411.github.io/blog/cve-2021-35448)
- [https://www.cve.org/CVERecord?id=CVE-2021-35448](https://www.cve.org/CVERecord?id=CVE-2021-35448)
- [https://www.exploit-db.com/exploits/50047](https://www.exploit-db.com/exploits/50047)