CVE-2022-42948
악용 확인 Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability
악용 여부
악용 확인
2023-03-30
2023-04-20
CISA 미확인
Fortra Cobalt Strike
심각도 (발행처 발표값)
심각9.8
3.1
NVD (미국 NIST)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
악용 확률 (EPSS)
2.7%
2.71%
85.0%
2026-09-04
한국어 공식 권고
CISA 원문
Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.— CISA KEV · shortDescription 원문
Apply updates per vendor instructions.— CISA KEV · requiredAction 원문
취약점 설명 (NVD 원문)
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.
CWE-116 CWE-116
이 페이지는 조치 지시가 아닙니다. 영향 범위와 패치 버전은 제품·구성에 따라 다르므로, 반드시 공급사 공식 권고와 NVD 원문의 참조 링크를 확인하세요.