Security readout for executives and security teams
Plain-English summary
Intel Remote Keyboard could let someone with local access inject keystrokes into another remote keyboard session. That can turn a local foothold into unauthorized actions under another session. The source bundle does not provide a severity score, confirmed fix, or active exploitation evidence.
Executive priority
Treat as a targeted exposure review, not a broad emergency, unless the software is present on sensitive or shared endpoints. Prioritize confirming deployment and following Intel guidance.
Technical view
CVE-2018-3645 affects all versions of Intel Remote Keyboard. The described weakness is escalation of privilege through keystroke injection into another remote keyboard session by a local attacker. No CVSS, CWE, exploit detail, or remediation text is included in the supplied bundle.
Likely exposure
Exposure is limited to environments where Intel Remote Keyboard is installed or used. The bundle lists all versions as affected but provides no platform, configuration, or deployment details.
Exploitation context
The supplied sources describe local attack requirements and cross-session keystroke injection. KEV status is false, and the bundle does not cite active exploitation or public exploit availability.
Researcher notes
Evidence is sparse. The core condition is local attacker access plus another remote keyboard session. Do not assume network exploitability, affected platforms, or patch availability beyond the Intel advisory reference.
Mitigation direction
- Inventory systems for Intel Remote Keyboard installations and active use.
- Review Intel advisory INTEL-SA-00122 for vendor-approved remediation or disposition.
- Remove or disable Intel Remote Keyboard where business use is not required.
- Restrict local access to systems that still require the software.
Validation and detection
- Confirm whether Intel Remote Keyboard exists in endpoint software inventories.
- Check whether any remote keyboard sessions are used on affected systems.
- Verify local users and support accounts with access to those endpoints.
- Track remediation status against Intel advisory INTEL-SA-00122.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-3645 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00122&languageid=en-frCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
