A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.
References
Link | Resource |
---|---|
https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/ | Exploit Third Party Advisory |
https://www.cobaltstrike.com/releasenotes.txt | Release Notes Vendor Advisory |
https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/ | Exploit Third Party Advisory |
https://www.cobaltstrike.com/releasenotes.txt | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/ - Exploit, Third Party Advisory | |
References | () https://www.cobaltstrike.com/releasenotes.txt - Release Notes, Vendor Advisory |
Information
Published : 2021-08-09 13:15
Updated : 2024-11-21 06:14
NVD link : CVE-2021-36798
Mitre link : CVE-2021-36798
CVE.ORG link : CVE-2021-36798
JSON object : View
Products Affected
helpsystems
- cobalt_strike
CWE
CWE-770
Allocation of Resources Without Limits or Throttling