CVE-2022-42948
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-116
מוצרים מושפעים
helpsystems: cobalt strike
קישורים
- https://www.cobaltstrike.com/blog/ Vendor Advisory
- https://www.cobaltstrike.com/blog/ Vendor Advisory
- https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerabilit… Technical DescriptionThird Party Advisory
- https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve… Third Party Advisory
- https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerabilit… Technical DescriptionThird Party Advisory
- https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve… Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource