A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.
References
Link | Resource |
---|---|
https://www.cobaltstrike.com/releasenotes.txt | Release Notes Vendor Advisory |
https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-halt-operations/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-08-09 06:15
Updated : 2021-08-17 05:49
NVD link : CVE-2021-36798
Mitre link : CVE-2021-36798
JSON object : View
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
Products Affected
helpsystems
- cobalt_strike