Umbra Wiki cve cve/CVE-2022-42948
Back to wiki

CVE-2022-42948 — Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2022-42948 · CWE: CWE-79 CWE-116

CVE-2022-42948: Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Fortra
Product Cobalt Strike
Date added 2023-03-30
Due date 2023-04-20
Ransomware campaign use Unknown

Description

Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-2/; https://nvd.nist.gov/vuln/detail/CVE-2022-42948

Weakness behind it

CISA records this vulnerability as an instance of CWE-79, CWE-116. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-42948
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →