CVE-2022-39197
KEVlargeXSS in Fortra Cobalt Strike Teamserver Enables Remote Code Execution
CISA: Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability
Fortra Cobalt Strike's Teamserver fails to properly validate the username field in a Beacon's configuration (CWE-20), producing a cross-site scripting flaw (CWE-79). An attacker who has already compromised a machine running a Cobalt Strike beacon can set a malformed username in the beacon configuration, and the injected content executes when it is rendered in the Teamserver, which the vendor notes can be escalated to executing code remotely on the Teamserver. Code execution on the Teamserver hands the attacker control of the C2 infrastructure itself, including beacon configurations, operator sessions, and the credentials and tooling managed there. Any organization running Fortra Cobalt Strike is affected, with risk highest where an operator is actively interacting with a Teamserver that has beacons from potentially compromised hosts. The flaw is already listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-03-30), carries a high EPSS score of about 46%, and no public proof-of-concept is recorded in the source data.
What to do: Apply Fortra's updated Cobalt Strike release as soon as possible, per the CISA KEV required action to apply updates per vendor instructions. Because triggering the flaw presupposes an existing beacon foothold, hunt for and evict active beacons in the environment and be cautious rendering content from untrusted beacons in the Teamserver UI. Confirm the team server is running the patched build before treating the finding as remediated.
| Fortra Cobalt Strike (Teamserver) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
- Affected
- Fortra Cobalt Strike
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- helpsystems
- Products
- cobalt strike
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N