ZeroHour

CVE-2022-31199

KEV ransomware PoC large

Unauthenticated Deserialization RCE in Netwrix Auditor Video Recording Component

CISA: Netwrix Auditor Insecure Object Deserialization Vulnerability

CVSS 3.1
9.8 critical
EPSS
36%p98
Published
()
KEV added
AI analysis

CVE-2022-31199 is an insecure object deserialization flaw (CWE-502; CISA also tags CWE-122) in the User Activity Video Recording component of Netwrix Auditor. An unauthenticated remote attacker who can reach the component's TCP port 9004 can trigger the flaw; this port is commonly blocked by standard enterprise firewalling, which limits how many environments are directly reachable. Successful exploitation yields arbitrary code execution running as NT AUTHORITY\SYSTEM, giving the attacker full local privileges on the affected host and a strong foothold for follow-on activity such as ransomware. Any organization running Netwrix Auditor with the User Activity Video Recording component deployed is affected, with the available data providing no specific affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11 with known ransomware use, and EPSS assigns a 36% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

What to do: Apply updates per vendor instructions immediately, or discontinue use of the affected component if updates are unavailable, per CISA's required action. Inventory whether the User Activity Video Recording component is installed and whether TCP port 9004 is reachable from user networks, VPNs, or the internet, and restrict that port to trusted hosts as a stopgap. Prioritize remediation given the KEV listing and known ransomware use.

Affected
Netwrix Auditor
Estimated exposure
large≈10,000–100,000 installations (estimated) — No install-base or internet-scan counts are present in the data; the estimate reflects Netwrix Auditor's role as a widely deployed enterprise IT-audit product, reduced because only deployments with the optional User Activity Video…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.

CISA Known Exploited Vulnerability
Affected
Netwrix Auditor
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Due date
Ransomware use
Known
Vendors
netwrix
Products
auditor
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news