Executive brief
Fortra Cobalt Strike 4.7.1 fails to properly escape HTML tags when displayed on Java Swing components. An attacker can inject crafted HTML code to achieve remote code execution within the Cobalt Strike user interface.
Affected products
- Fortra (formerly HelpSystems) Cobalt Strike 4.7.1
Timeline
- 2023-03-24: disclosed: NVD Published Date
- 2023-03-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-03-30: advisory: Initial NIST NVD analysis published