← Vulnerability feed

Vulnerability record · CVE-2022-42948 · published 24 March 2023

CVE-2022-42948: Cobalt Strike UI HTML injection leads to remote code execution

Helpsystems · Cobalt Strike

Cobalt Strike 4.7.1 fails to escape HTML tags rendered in its Swing UI components. Crafted HTML injected into that UI can execute code in the Cobalt Strike client context. Because Cobalt Strike is a red-team tool, compromise of its operator UI can expose or subvert active operations.

9.8 CVSS 3.1 Critical CISA KEV since 30 Mar 2023 EPSS 2.7% · top 14.6% CWE-116 · CWE-116
9.8CVSS 3.1 base score
2.7%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and confirmed CISA KEV exploitation make this a critical fix-first item.

What it is

Cobalt Strike 4.7.1 fails to escape HTML tags rendered in its Swing UI components. Crafted HTML injected into that UI can execute code in the Cobalt Strike client context. Because Cobalt Strike is a red-team tool, compromise of its operator UI can expose or subvert active operations.

Impact

An attacker who can get crafted HTML into the Cobalt Strike UI can execute code in the operator's client, gaining the operator's privileges and access to the tooling and data it manages.

Attack surface

The CVSS vector is network reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the flaw is reachable over the network without authentication. The description does not specify the exact injection path into the Swing UI.

Exploitation

CVE-2022-42948 is listed in CISA KEV with a due date of 2023-04-20, indicating known exploitation. EPSS 30-day probability is 0.02706 (85th percentile), and references are vendor and third-party advisories rather than public exploit code.

What to do

  • Upgrade Cobalt Strike to a version later than 4.7.1 per the vendor advisory.
  • If an upgrade is not immediately possible, restrict network access to the Cobalt Strike client and team server to trusted hosts only.
  • Treat the Cobalt Strike UI host as high value: isolate it, limit credentials and data it can reach, and monitor it closely.
  • Review CISA KEV required actions and confirm remediation by the 2023-04-20 due date.
  • Audit who can send content into the Cobalt Strike UI and remove untrusted sources.

Detection

  • Monitor for unexpected child processes spawned by the Cobalt Strike client process.
  • Alert on network connections to the Cobalt Strike client or team server from untrusted hosts.
  • Review Cobalt Strike client logs and UI activity for injected or malformed HTML content.
  • Hunt for post-exploitation activity originating from hosts running the Cobalt Strike client.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-42948 to the Known Exploited Vulnerabilities catalog on 30 March 2023 as "Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 20 April 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-42948 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2022-39197Cobalt Strike Teamserver XSS via Malformed Payload Username FieldCobalt Strike through 4.7 contains a cross-site scripting flaw in the teamserver that lets a remote attacker inject HTML by modifying the username fi…KEVEPSS 46%analysed7.5CVE-2022-23317Helpsystems cobalt strike improper authentication vulnerabilityCobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain relevant information by spec…EPSS 1.1%7.5CVE-2021-36798Helpsystems cobalt strike allocation without limits vulnerabilityA Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash t…EPSS 4.3%7.8CVE-2026-20245Cisco Catalyst SD-WAN CLI command injection via crafted file uploadCisco Catalyst SD-WAN Controller, Manager and Validator fail to properly validate user-supplied input in the CLI, allowing an authenticated local att…KEVEPSS 25%analysed9.1CVE-2024-38475Apache HTTP Server mod_rewrite improper escaping enables code executionApache HTTP Server 2.4.59 and earlier has an improper output escaping flaw in mod_rewrite. Substitutions in server context that use a backreference o…KEVEPSS 100%analysed6.1CVE-2022-24682Zimbra Collaboration Suite Calendar stored XSS via unescaped HTML attributesThe Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1) fails to escape HTML placed inside element attributes, all…KEVEPSS 31%analysed

Source: NIST National Vulnerability Database (record CVE-2022-42948), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.