CVE-2025-66576CRITICAL 9.8EPSS p60.0%

CVE-2025-66576CVE-2025-66576

Description

Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.05% probability of exploitation · percentile 60.0% · 2026-06-18T12:00:27Z
Published2025-12-04
Last modified2025-12-17

Underlying weaknesses· 1

CWE-78

References

  1. https://apps.microsoft.com/detail/9n0jw8v5sc9m?hl=neutral&gl=US&ocid=pdpshare
  2. https://remotecontrolio.web.app/
  3. https://www.exploit-db.com/exploits/52299
  4. https://www.vulncheck.com/advisories/remote-keyboard-desktop-101-remote-code-execution-rce
  5. https://www.exploit-db.com/exploits/52299

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-780%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-21297
CVE
CVE-2026-48563
CVE
CVE-2025-26645
CVE
CVE-2025-29966
CVE
CVE-2025-48817
CVE
CVE-2026-42985
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.