ZeroHour
Security Affairspublished ()ingested @securityaffairs

Critical RCE impacts popular post

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-39197
XSS in Fortra Cobalt Strike Teamserver Enables Remote Code Execution

Fortra Cobalt Strike's Teamserver fails to properly validate the username field in a Beacon's configuration (CWE-20), producing a cross-site scripting flaw (CWE-79). An attacker who has already compromised a machine running a Cobalt Strike beacon can set a malformed username in the beacon configuration, and the injected content executes when it is rendered in the Teamserver, which the vendor notes can be escalated to executing code remotely on the Teamserver. Code execution on the Teamserver hands the attacker control of the C2 infrastructure itself, including beacon configurations, operator sessions, and the credentials and tooling managed there. Any organization running Fortra Cobalt Strike is affected, with risk highest where an operator is actively interacting with a Teamserver that has beacons from potentially compromised hosts. The flaw is already listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-03-30), carries a high EPSS score of about 46%, and no public proof-of-concept is recorded in the source data.

Do: Apply Fortra's updated Cobalt Strike release as soon as possible, per the CISA KEV required action to apply updates per vendor instructions. Because triggering the flaw presupposes an existing beacon foothold, hunt for and evict active beacons in the environment and be cautious rendering content from untrusted beacons in the Teamserver UI. Confirm the team server is running the patched build before treating the finding as remediated.

6.146% KEV
  • Fortra Cobalt Strike (Teamserver)
largetens of thousands of internet-exposed Cobalt Strike Team servers (roughly 20,000-50,000 per public scans), with total deployments likely higher
CVE-2022-42948
HTML Injection RCE in Fortra (HelpSystems) Cobalt Strike UI

Fortra (formerly HelpSystems) Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are rendered in the Swing components of its user interface, an improper-escaping flaw (CWE-116). An attacker who can cause crafted HTML — for example, content delivered through beacon or team-server data and displayed in the console — to appear in the UI can trigger remote code execution in the Cobalt Strike client, consistent with the CVSS 3.1 score of 9.8 (network vector, low complexity, no privileges or user interaction required). Successful exploitation yields code execution on the machine running the Cobalt Strike UI, typically the operator's workstation, potentially exposing the attacker's or red teamer's tooling, active C2 sessions, and any environments they are connected to. Anyone running the affected release is exposed, including users of unlicensed/copied installations, which are widespread in both legitimate and criminal use of this tool. The bug is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-03-30, with press reports linking its exploitation to commercial surveillance spyware), carries an EPSS of about 2.7%, and no public PoC is known; one related headline notes the vendor's patch initially fell short, so defenders should verify they are running a fully fixed build.

Do: Apply updates per Fortra/HelpSystems instructions (the CISA KEV required action) and confirm the running Cobalt Strike client and team server are on a build with the complete HTML-escaping fix, since the vendor's first patch reportedly fell short. Until patched, treat UI-rendered beacon and event content as untrusted input and limit team-server exposure to untrusted networks.

9.83% KEV
  • Fortra (HelpSystems) Cobalt Strike 4.7.1 (version cited in the CVE description as failing to escape HTML tags; CISA lists Fortra Cobalt Strike as affected)
moderate≈ thousands of internet-exposed Cobalt Strike team servers and tens of thousands of practitioner users
Full article426 words · extracted from securityaffairs.com · click to collapse

HelpSystems, the company that developed the Cobalt Strike platform, addressed a critical remote code execution vulnerability in its software.

HelpSystems, the company that developed the commercial post-exploitation toolkit Cobalt Strike, addressed a critical remote code execution vulnerability, tracked as CVE-2022-42948, in its platform.

The company released an out-of-band security update to address the remote code execution issue that can be exploited by an attacker to take control of targeted systems.

“Certain components within Java Swing will automatically interpret any text as HTML content if it starts with <html>. This can be exploited using an object tag, which in turn can load a malicious payload from a webserver, which is then executed by the Cobalt Strike client.” reads the post published by HelpSystems. “Disabling automatic parsing of html tags across the entire client was enough to mitigate this behaviour.”

The vulnerability affects Cobalt Strike version 4.7.1 and results from an incomplete patch released on September 20, 2022, to address cross-site scripting (XSS) vulnerability tracked as CVE-2022-39197.

An attacker can exploit the CVE-2022-39197 by manipulating some client-side UI input fields, by simulating a Cobalt Strike implant check-in or by hooking a Cobalt Strike implant running on a host.

HelpSystems reported that the remote code execution could be triggered in specific cases using the Java Swing framework used by the popular toolkit. The flaw was addressed with the release of Cobalt Strike 4.7.2. The company highlighted that this flaw isn’t specific to Cobalt Strike software and for this reason, it hasn’t assigned it a new CVE. 

“This is an out of band update to fix a remote code execution vulnerability that is rooted in Java Swing but which can be exploited in Cobalt Strike.” reads a post published by the vendor.

Threat actors could exploit the flaw by leveraging an HTML <object> tag to load a malicious payload hosted on a remote server and inject it within the note field or the graphical file explorer menu in the post-exploitation platform UI.

Below is an image that demonstrates IBM researchers successfully triggered the vulnerability and executed /usr/bin/xcalc.

Cobalt Strike

“It should be noted here that this is a very powerful exploitation primitive. Since we can write a payload in Java, this means that we can construct a fully featured cross-platform payload that would be able to execute code on the user’s machine regardless of the operating system flavor or architecture.” wrote IBM researchers that also published a video PoC.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, RCE)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/137284/hacking/cobalt-strike-rce.html