CVE-2022-31199
Netwrix Auditor Insecure Object Deserialization Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 August 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 36.01% probability · 98th percentile
- CISA KEV
- Listed 11 July 2023 · due 1 August 2023 · used in ransomware campaigns
- Weakness
- CWE-502
- Affected
- netwrix/auditor
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Patch application requires login to customer portal: https://security.netwrix.com/Account/SignIn?ReturnUrl=%2FAdvisories%2FADV-2022-003; https://nvd.nist.gov/vuln/detail/CVE-2022-31199
References
- https://bishopfox.com/blog/netwrix-auditor-advisoryExploit, Third Party Advisory
- https://bishopfox.com/blog/netwrix-auditor-advisoryExploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-31199US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.