{"id":3913,"date":"2025-05-13T10:02:06","date_gmt":"2025-05-13T10:02:06","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/13\/cobalt-strike-4-11-1-released-with-fix-for-enable-ssl-checkbox\/"},"modified":"2025-05-13T10:02:06","modified_gmt":"2025-05-13T10:02:06","slug":"cobalt-strike-4-11-1-released-with-fix-for-enable-ssl-checkbox","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/13\/cobalt-strike-4-11-1-released-with-fix-for-enable-ssl-checkbox\/","title":{"rendered":"Cobalt Strike 4.11.1 Released With Fix For \u2018Enable SSL\u2019 Checkbox"},"content":{"rendered":"<p>    Cobalt Strike 4.11.1 Released With Fix For \u2018Enable SSL\u2019 Checkbox<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Fortra has released <a href=\"https:\/\/cybersecuritynews.com\/red-team-tool-cobalt-strike-4-11-released\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cobalt Strike<\/a> 4.11.1, an out-of-band update addressing critical issues discovered in their recent 4.11 release.\u00a0<\/p>\n<p>This update, released on May 12, 2025, focuses primarily on resolving module stomping complications while also addressing issues with SSL certificate functionality and adding deprecation warnings for legacy features.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Module Stomping Crash Resolved<\/strong><\/h2>\n<p>The most significant fix resolves a critical issue where Beacon would crash under specific conditions when using module stomping in conjunction with the new ObfSetThreadContext injection technique introduced in version 4.11.\u00a0<\/p>\n<p>This crash occurred specifically when targeting processes with Control Flow Guard enabled.<\/p>\n<p>\u201cWe fixed an issue which caused Beacon to crash in edge cases when module stomping was used in conjunction with ObfSetThreadContext injection when the target process had Control Flow Guard enabled,\u201d <a href=\"https:\/\/www.cobaltstrike.com\/blog\/out-of-band-update-cobalt-strike-4111\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">stated<\/a> the official release announcement.\u00a0<\/p>\n<p>A patch has been implemented to address this vulnerability. For users implementing User Defined Reflective Loaders (UDRL) that perform module stomping, Fortra recommends explicitly setting the METHOD_MODULESTOMP parameter as part of the ALLOCATED_MEMORY structure in their UDRL implementation.\u00a0<\/p>\n<p>This ensures Beacon remains aware of potential Control Flow Guard related issues. The team recommends referencing the bud-loader in UDRL-vs, included in the Cobalt Strike arsenal kit, for implementation examples.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Fix for \u2018Enable SSL\u2019 Checkbox\u00a0<\/strong><\/h2>\n<p>The update also resolves a significant usability issue with the \u201cEnable SSL\u201d checkbox functionality.\u00a0<\/p>\n<p>Previously, when users configured a self-signed certificate via the \u2018https-certificate\u2019 setting, the \u2018Enable SSL\u2019 checkbox would become disabled, preventing HTTPS from being enabled.\u00a0<\/p>\n<p>With version 4.11.1, self-signed certificates properly enable the checkbox functionality, allowing users to implement secure communications with their <a href=\"https:\/\/cybersecuritynews.com\/microsoft-entra-refresh-tokens-via-beacon\/\" target=\"_blank\" rel=\"noreferrer noopener\">Beacon infrastructure<\/a>.<\/p>\n<p>Cobalt Strike documentation provides two approaches for SSL certificate implementation:<\/p>\n<ul class=\"wp-block-list\">\n<li>Self-signed SSL certificates, configurable through parameters including Country (C), Common Name (CN), Organization (O), and validity period<\/li>\n<li>Valid SSL certificates using Java Keystore files with proper certificate information<\/li>\n<\/ul>\n<p>The release also introduces explicit deprecation warnings for stomp reflective loaders in the c2lint program.\u00a0<\/p>\n<p>This follows the team\u2019s announcement in the 4.11 release that they are transitioning to prepend loaders as the default mechanism.\u00a0<\/p>\n<p>The c2lint utility will now display warnings when stomp loaders are used, reinforcing the pending end of support in future releases.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Update Now<\/strong><\/h2>\n<p>The 4.11.1 update comes just two months after the major 4.11 release, which introduced significant new functionality including a novel Sleepmask for runtime obfuscation, the ObfSetThreadContext process <a href=\"https:\/\/cybersecuritynews.com\/appdomainmanager-injection-to-execute-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\">injection technique<\/a>, and DNS over HTTPS (DoH) Beacon capabilities.<\/p>\n<p>Licensed users can download version 4.11.1 immediately from Fortra\u2019s website. Organizations managing existing Cobalt Strike environments that don\u2019t require immediate updating can alternatively obtain a new authorization file using the Authorization Generation page rather than performing a full update.<\/p>\n<p>This rapid out-of-band release demonstrates Fortra\u2019s commitment to quickly addressing critical issues in their red team simulation platform, which has become an essential tool for security professionals conducting advanced adversary emulation exercises.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 84%,rgb(169,184,195) 100%)\"><strong>Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points \u2013 <a href=\"https:\/\/webinars.indusface.com\/15-minute-vulnerability-attack-simulation-insights-to-fortify-edge\/register?utm_source=gbhackers-blog-cta&amp;utm_campaign=2025-may-webinar-vulnerability&amp;utm_medium=referral\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cobalt-strike-4-11-1-released\/\">Cobalt Strike 4.11.1 Released With Fix For \u2018Enable SSL\u2019 Checkbox<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Kaaviya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cobalt-strike-4-11-1-released\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cobalt Strike 4.11.1 Released With Fix For \u2018Enable SSL\u2019 Checkbox Fortra has released Cobalt Strike 4.11.1, an out-of-band update addressing critical issues discovered in their recent 4.11 release.\u00a0 This update, released on May 12, 2025, focuses primarily on resolving module stomping complications while also addressing issues with SSL certificate functionality and adding deprecation warnings for [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,1263,131],"tags":[130],"class_list":["post-3913","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-ssl","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3913"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3913"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3913\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3913"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}