Junglewise Threat Intelligence

CVE-2022-31199: Netwrix Auditor Insecure Object Deserialization Vulnerability

CVE-2022-31199 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-07-11

Executive brief

Netwrix Auditor's User Activity Video Recording component contains an insecure object deserialization vulnerability. An unauthenticated remote attacker can exploit this by reaching port 9004/TCP to execute arbitrary code with NT AUTHORITY\SYSTEM privileges on the server and monitored agents.

Affected products

  • Netwrix Auditor Up to (excluding) 10.5

Timeline

  • 2022-11-07: disclosed: NVD Published Date
  • 2023-07-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-07-11: exploited: Reported as exploited in the wild in advisory summary