Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
References
| Link | Resource |
|---|---|
| https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical Description Third Party Advisory |
| https://www.cobaltstrike.com/blog/ | Vendor Advisory |
| https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
| https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ | Technical Description Third Party Advisory |
| https://www.cobaltstrike.com/blog/ | Vendor Advisory |
| https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-42948 |
Configurations
History
22 Oct 2025, 00:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 07:25
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ - Technical Description, Third Party Advisory | |
| References | () https://www.cobaltstrike.com/blog/ - Vendor Advisory | |
| References | () https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ - Third Party Advisory |
08 Aug 2023, 14:21
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-116 |
30 Mar 2023, 18:30
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| CPE | cpe:2.3:a:helpsystems:cobalt_strike:4.7.1:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| References | (MISC) https://www.redpacketsecurity.com/helpsystems-cobalt-strike-code-execution-cve-2022-42948/ - Third Party Advisory | |
| References | (MISC) https://www.cobaltstrike.com/blog/ - Vendor Advisory | |
| References | (MISC) https://thesecmaster.com/how-to-fix-cve-2022-42948-a-critical-rce-vulnerability-in-cobalt-strike/ - Technical Description, Third Party Advisory |
24 Mar 2023, 17:57
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-03-24 14:15
Updated : 2025-10-22 00:18
NVD link : CVE-2022-42948
Mitre link : CVE-2022-42948
CVE.ORG link : CVE-2022-42948
JSON object : View
Products Affected
helpsystems
- cobalt_strike
CWE
CWE-116
Improper Encoding or Escaping of Output
