CVE-2022-42948
Last modified
CVE-2022-42948 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.. CISA has confirmed active exploitation in the wild. EPSS estimates a 2.71% chance of exploitation in the next 30 days.
Description
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Helpsystems | Cobalt Strike | 4.7.1 |
References
- https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/Technical Description, Third Party Advisory
- https://www.cobaltstrike.com/blog/Vendor Advisory
- https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/Technical Description, Third Party Advisory
- https://www.cobaltstrike.com/blog/Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-42948US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2022-42948?
How severe is CVE-2022-42948?
How do I fix CVE-2022-42948?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-42942A malicious crafted dwf or .pct file when consumed through D…7.8
- CVE-2022-42943A malicious crafted dwf or .pct file when consumed through D…7.8
- CVE-2022-42944A malicious crafted dwf or .pct file when consumed through D…7.8
- CVE-2022-42945DWG TrueViewTM 2023 version has a DLL Search Order Hijacking…7.8
- CVE-2022-42946Parsing a maliciously crafted X_B and PRT file can force Aut…7.1
- CVE-2022-42947A maliciously crafted X_B file when parsed through Autodesk …7.8
- CVE-2022-42949Silverstripe silverstripe/subsites through 2.6.0 has Insecur…7.5
- CVE-2022-4295The Show All Comments WordPress plugin before 7.0.1 does not…6.1
- CVE-2022-42950An issue was discovered in Couchbase Server 7.x before 7.0.5…4.9
- CVE-2022-42951An issue was discovered in Couchbase Server 6.5.x and 6.6.x …8.1
- CVE-2022-42953Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM…7.5
- CVE-2022-42954Keyfactor EJBCA before 7.10.0 allows XSS.5.4
Are you affected by CVE-2022-42948?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
