Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
References
Link | Resource |
---|---|
https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical Description Third Party Advisory |
https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical Description Third Party Advisory |
https://www.cobaltstrike.com/blog/ | Vendor Advisory |
https://www.cobaltstrike.com/blog/ | Vendor Advisory |
https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
Configurations
History
28 Jan 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ - Third Party Advisory | |
References | () https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ - Technical Description, Third Party Advisory | |
References | () https://www.cobaltstrike.com/blog/ - Vendor Advisory |
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-116 |
Information
Published : 2023-03-24 14:15
Updated : 2025-02-07 14:53
NVD link : CVE-2022-42948
Mitre link : CVE-2022-42948
JSON object : View
Products Affected
helpsystems
- cobalt_strike
CWE
CWE-116
Improper Encoding or Escaping of Output