First published: Fri Mar 24 2023(Updated: )
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HelpSystems Cobalt Strike | =4.7.1 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42948 is a vulnerability in Fortra Cobalt Strike User Interface that allows remote code execution.
The affected software for CVE-2022-42948 is Fortra Cobalt Strike.
The vulnerability in CVE-2022-42948 is rooted in Java Swing within the Fortra Cobalt Strike User Interface.
The severity of CVE-2022-42948 is not specified.
Yes, a fix for CVE-2022-42948 is available in the latest update of Fortra Cobalt Strike (version 4.7.2).