CISA Known Exploited Vulnerability

CVE-2022-42948

Fortra · Cobalt Strike

Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability

Date added
BOD 22-01 due date
CWE CWE-79, CWE-116
Ransomware Unknown

CISA description

Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote code execution.

Required action

Apply updates per vendor instructions.