SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-42948

Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 2.71%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 20 April 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.71% probability · 85th percentile
CISA KEV
Listed 30 March 2023 · due 20 April 2023
Weakness
CWE-116
Affected
helpsystems/cobalt strike
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-2/; https://nvd.nist.gov/vuln/detail/CVE-2022-42948

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.