Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-41477

Опубликовано: 24 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with WorldAccessOption enabled. The daemon processes privileged commands without authentication, allowing any local unprivileged user to execute arbitrary commands as SYSTEM. Affects both stable v1.20.0 + and Continuous v1.26.0.134 prerelease.

РелизСтатусПримечание
devel

not-affected

only affects windows
esm-apps/resolute

not-affected

only affects windows
jammy

DNE

noble

DNE

questing

not-affected

only affects windows
resolute

not-affected

only affects windows
upstream

not-affected

debian: Only affect Deskflow on Windows

Показывать по

EPSS

Процентиль: 13%
0.00218
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
4 месяца назад

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with WorldAccessOption enabled. The daemon processes privileged commands without authentication, allowing any local unprivileged user to execute arbitrary commands as SYSTEM. Affects both stable v1.20.0 + and Continuous v1.26.0.134 prerelease.

CVSS3: 7.8
debian
4 месяца назад

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, ...

EPSS

Процентиль: 13%
0.00218
Низкий

7.8 High

CVSS3