SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-31199

Netwrix Auditor Insecure Object Deserialization Vulnerability

KEVCRITICAL 9.8EPSS 36.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 August 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
36.01% probability · 98th percentile
CISA KEV
Listed 11 July 2023 · due 1 August 2023 · used in ransomware campaigns
Weakness
CWE-502
Affected
netwrix/auditor
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Patch application requires login to customer portal: https://security.netwrix.com/Account/SignIn?ReturnUrl=%2FAdvisories%2FADV-2022-003; https://nvd.nist.gov/vuln/detail/CVE-2022-31199

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.