Executive brief
Netwrix Auditor's User Activity Video Recording component contains an insecure object deserialization vulnerability. An unauthenticated remote attacker can exploit this by reaching port 9004/TCP to execute arbitrary code with NT AUTHORITY\SYSTEM privileges on the server and monitored agents.
Affected products
- Netwrix Auditor Up to (excluding) 10.5
Timeline
- 2022-11-07: disclosed: NVD Published Date
- 2023-07-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-07-11: exploited: Reported as exploited in the wild in advisory summary