ZeroHour

CVE-2022-42948

KEVmoderate

HTML Injection RCE in Fortra (HelpSystems) Cobalt Strike UI

CISA: Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
KEV added
AI analysis

Fortra (formerly HelpSystems) Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are rendered in the Swing components of its user interface, an improper-escaping flaw (CWE-116). An attacker who can cause crafted HTML — for example, content delivered through beacon or team-server data and displayed in the console — to appear in the UI can trigger remote code execution in the Cobalt Strike client, consistent with the CVSS 3.1 score of 9.8 (network vector, low complexity, no privileges or user interaction required). Successful exploitation yields code execution on the machine running the Cobalt Strike UI, typically the operator's workstation, potentially exposing the attacker's or red teamer's tooling, active C2 sessions, and any environments they are connected to. Anyone running the affected release is exposed, including users of unlicensed/copied installations, which are widespread in both legitimate and criminal use of this tool. The bug is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-03-30, with press reports linking its exploitation to commercial surveillance spyware), carries an EPSS of about 2.7%, and no public PoC is known; one related headline notes the vendor's patch initially fell short, so defenders should verify they are running a fully fixed build.

What to do: Apply updates per Fortra/HelpSystems instructions (the CISA KEV required action) and confirm the running Cobalt Strike client and team server are on a build with the complete HTML-escaping fix, since the vendor's first patch reportedly fell short. Until patched, treat UI-rendered beacon and event content as untrusted input and limit team-server exposure to untrusted networks.

Affected
Fortra (HelpSystems) Cobalt Strike4.7.1 (version cited in the CVE description as failing to escape HTML tags; CISA lists Fortra Cobalt Strike as affected)
Estimated exposure
moderate≈ thousands of internet-exposed Cobalt Strike team servers and tens of thousands of practitioner users — Public internet-wide scans have repeatedly shown on the order of thousands of Cobalt Strike team servers reachable online, and the tool is the de facto standard red-team C2 with a large licensed install base plus widespread cracked copies,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

CISA Known Exploited Vulnerability
Affected
Fortra Cobalt Strike
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
helpsystems
Products
cobalt strike
Weakness
CWE-116
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news