CVE-2022-42948

Fortra Cobalt Strike: User Interface Remote Code Execution

As of , CVE-2022-42948 in Fortra Cobalt Strike is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch soon.

Exploited
Yes: CISA listed it on 30 March 2023
US federal deadline
20 April 202321 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.03Higher than 85% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.00 on 30 March 2023EPSS on the day CISA listed it.
Public exploit
None foundNeither Metasploit nor Exploit-DB lists one.
Fix
Vendor advice: www.cobaltstrike.comLinks below, from CISA's entry.

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.

CISA's description

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

The CVE record's description, from mitre

CVE published
24 March 2023
Assigned by
mitre
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-116
Improper Encoding or Escaping of Output
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.

Cobalt Strike: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2022-39197Teamserver Cross-Site Scripting (XSS)Fortra Cobalt StrikePatch soon0.46

Read further