Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
References
Link | Resource |
---|---|
https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical Description Third Party Advisory |
https://www.cobaltstrike.com/blog/ | Vendor Advisory |
https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical Description Third Party Advisory |
https://www.cobaltstrike.com/blog/ | Vendor Advisory |
https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
Configurations
History
21 Nov 2024, 07:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ - Technical Description, Third Party Advisory | |
References | () https://www.cobaltstrike.com/blog/ - Vendor Advisory | |
References | () https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ - Third Party Advisory |
08 Aug 2023, 14:21
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-116 |
Information
Published : 2023-03-24 14:15
Updated : 2024-11-21 07:25
NVD link : CVE-2022-42948
Mitre link : CVE-2022-42948
CVE.ORG link : CVE-2022-42948
JSON object : View
Products Affected
helpsystems
- cobalt_strike
CWE
CWE-116
Improper Encoding or Escaping of Output