CVE-2022-42948

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

  • Published Mar 24, 2023
  • CVSS 9.8 critical
  • 2.7% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

CVE-2022-42948 at the National Vulnerability Database