A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.
References
Link | Resource |
---|---|
https://www.cobaltstrike.com/releasenotes.txt | Release Notes Vendor Advisory |
https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-08-09 13:15
Updated : 2021-08-17 12:49
NVD link : CVE-2021-36798
Mitre link : CVE-2021-36798
JSON object : View
Products Affected
helpsystems
- cobalt_strike
CWE
CWE-770
Allocation of Resources Without Limits or Throttling