SOURCE FACT
Fortra · Cobalt Strike
Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.
Required action
Apply updates per vendor instructions.
CISA notes
https://www.cobaltstrike.com/blog/out-of-band-update-cobalt-strike-4-7-2/; https://nvd.nist.gov/vuln/detail/CVE-2022-42948
View source evidence →