CVE-2022-42948

9.8CRITICAL

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

发布于: 3/24/2023更新于: 11/3/2025

CISA已知被利用漏洞

Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.

所需操作:

Apply updates per vendor instructions.

截止日期:

2023-04-20

描述

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

AI分析AI驱动

受影响产品

helpsystemscobalt_strike
4.7.1

参考资料