CRITICAL

CVE-2022-42948

Helpsystems Cobalt Strike 2023-03-24 CVSS v3.1
CVSS
9.8
KEV

Description

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

Summary dbcve.org

Cobalt Strike 4.7.1 contains an HTML injection vulnerability in its Swing-based UI components where HTML tags are not properly escaped before rendering. This allows an attacker to inject malicious HTML/JavaScript code that executes within the context of the Cobalt Strike client, leading to remote code execution on the operator's machine.

Mitigation

Upgrade to Cobalt Strike 4.7.2 or later which contains the proper HTML escaping fix. Until then, avoid processing untrusted data through Cobalt Strike's UI and restrict network access to the team server.

Weakness (CWE)

CWE-116

EPSS Score

2.71%
Probability of exploitation in next 30 days
85.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE