CVE-2022-42948 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 2.7% (pctl 85)
Patch first
On CISA KEV — known exploited in the wild, due 2023-04-20.
Description
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.71% — more likely to be exploited than 85% of all CVEs |
| Weakness | CWE-116 |
| On CISA KEV | yes — remediate by 2023-04-20 |
| Public exploit | none known |
| Published | 2023-03-24 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability |
|---|---|
| Added | 2023-03-30 |
| Due | 2023-04-20 |
| Vendor / product | Fortra / Cobalt Strike |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| helpsystems | cobalt strike |
References
- https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/
- https://www.cobaltstrike.com/blog/
- https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/
- https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/
- https://www.cobaltstrike.com/blog/
- https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-42948
→ the Explorer · watch your stack · NVD