VulnerabilityAnalyzed
CVE-2022-42948
Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
KEVCRITICAL 9.8EPSS 2.71%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 20 April 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.71% probability · 85th percentile
- CISA KEV
- Listed 30 March 2023 · due 20 April 2023
- Weakness
- CWE-116
- Affected
- helpsystems/cobalt strike
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-2/; https://nvd.nist.gov/vuln/detail/CVE-2022-42948
References
- https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/Technical Description, Third Party Advisory
- https://www.cobaltstrike.com/blog/Vendor Advisory
- https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/Third Party Advisory
- https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/Technical Description, Third Party Advisory
- https://www.cobaltstrike.com/blog/Vendor Advisory
- https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-42948US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.