CRITICAL
CVE-2022-42948
CVSS
9.8
KEV
Description
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Summary dbcve.org
Cobalt Strike 4.7.1 contains an HTML injection vulnerability in its Swing-based UI components where HTML tags are not properly escaped before rendering. This allows an attacker to inject malicious HTML/JavaScript code that executes within the context of the Cobalt Strike client, leading to remote code execution on the operator's machine.
Mitigation
Upgrade to Cobalt Strike 4.7.2 or later which contains the proper HTML escaping fix. Until then, avoid processing untrusted data through Cobalt Strike's UI and restrict network access to the team server.
Weakness (CWE)
CWE-116
EPSS Score
2.71%
Probability of exploitation in next 30 days
85.3th percentile
References
https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/
Technical Description, Third Party Advisory
https://www.cobaltstrike.com/blog/
Vendor Advisory
https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-42948
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.