Vulnerability record · CVE-2022-42948 · published 24 March 2023
CVE-2022-42948: Cobalt Strike UI HTML injection leads to remote code execution
Helpsystems · Cobalt Strike
Cobalt Strike 4.7.1 fails to escape HTML tags rendered in its Swing UI components. Crafted HTML injected into that UI can execute code in the Cobalt Strike client context. Because Cobalt Strike is a red-team tool, compromise of its operator UI can expose or subvert active operations.
Description
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and confirmed CISA KEV exploitation make this a critical fix-first item.
What it is
Cobalt Strike 4.7.1 fails to escape HTML tags rendered in its Swing UI components. Crafted HTML injected into that UI can execute code in the Cobalt Strike client context. Because Cobalt Strike is a red-team tool, compromise of its operator UI can expose or subvert active operations.
Impact
An attacker who can get crafted HTML into the Cobalt Strike UI can execute code in the operator's client, gaining the operator's privileges and access to the tooling and data it manages.
Attack surface
The CVSS vector is network reachable with no privileges and no user interaction (AV:N/AC:L/PR:N/UI:N), so the flaw is reachable over the network without authentication. The description does not specify the exact injection path into the Swing UI.
Exploitation
CVE-2022-42948 is listed in CISA KEV with a due date of 2023-04-20, indicating known exploitation. EPSS 30-day probability is 0.02706 (85th percentile), and references are vendor and third-party advisories rather than public exploit code.
What to do
- Upgrade Cobalt Strike to a version later than 4.7.1 per the vendor advisory.
- If an upgrade is not immediately possible, restrict network access to the Cobalt Strike client and team server to trusted hosts only.
- Treat the Cobalt Strike UI host as high value: isolate it, limit credentials and data it can reach, and monitor it closely.
- Review CISA KEV required actions and confirm remediation by the 2023-04-20 due date.
- Audit who can send content into the Cobalt Strike UI and remove untrusted sources.
Detection
- Monitor for unexpected child processes spawned by the Cobalt Strike client process.
- Alert on network connections to the Cobalt Strike client or team server from untrusted hosts.
- Review Cobalt Strike client logs and UI activity for injected or malformed HTML content.
- Hunt for post-exploitation activity originating from hosts running the Cobalt Strike client.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-42948 to the Known Exploited Vulnerabilities catalog on 30 March 2023 as "Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 20 April 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical DescriptionThird Party Advisory |
| https://www.cobaltstrike.com/blog/ | Vendor Advisory |
| https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
| https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical DescriptionThird Party Advisory |
| https://www.cobaltstrike.com/blog/ | Vendor Advisory |
| https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-42948 | US Government Resource |
Track CVE-2022-42948 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-42948), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.