CVE-2021-36798
HIGH 7.5EPSS 4.3%
A Denial-of-Service (DoS) vulnerability was discovered in Team Server in HelpSystems Cobalt Strike 4.2 and 4.3. It allows remote attackers to crash the C2 server thread and block beacons' communication with it.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P - EPSS
- 4.29% chance of exploitation in the next 30 days, 90th percentile
- Published
- 2021-08-09
- Updated
- 2024-08-04
Proof-of-concept exploits (3)
- https://labs.sentinelone.com/hotcobalt-new-cobalt-strike-dos-vulnerability-that-lets-you-…
- JamVayne/CobaltStrikeDos103★ · 2021-09-26
- M-Kings/CVE-2021-3679836★ · 2021-08-19