Skip to content
COOEY

EXPOSURES › CVE-2022-42948

CVE-2022-42948

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-03-30 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-42948 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Fortra Cobalt Strike UI RCE

Fortra's Cobalt Strike User Interface was exploited remotely, enabling arbitrary code execution due to an unspecified Java Swing vulnerability.

Shame score — Actively exploited in the wild with no patch available.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.