Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
References
| Link | Resource |
|---|---|
| https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
| https://www.cobaltstrike.com/blog/ | Vendor Advisory |
| https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical Description Third Party Advisory |
Configurations
Information
Published : 2023-03-24 14:15
Updated : 2023-08-08 14:21
NVD link : CVE-2022-42948
Mitre link : CVE-2022-42948
JSON object : View
Products Affected
helpsystems
- cobalt_strike
CWE
CWE-116
Improper Encoding or Escaping of Output
