CVE-2022-31199
KEV ransomware PoC largeUnauthenticated Deserialization RCE in Netwrix Auditor Video Recording Component
CISA: Netwrix Auditor Insecure Object Deserialization Vulnerability
CVE-2022-31199 is an insecure object deserialization flaw (CWE-502; CISA also tags CWE-122) in the User Activity Video Recording component of Netwrix Auditor. An unauthenticated remote attacker who can reach the component's TCP port 9004 can trigger the flaw; this port is commonly blocked by standard enterprise firewalling, which limits how many environments are directly reachable. Successful exploitation yields arbitrary code execution running as NT AUTHORITY\SYSTEM, giving the attacker full local privileges on the affected host and a strong foothold for follow-on activity such as ransomware. Any organization running Netwrix Auditor with the User Activity Video Recording component deployed is affected, with the available data providing no specific affected version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11 with known ransomware use, and EPSS assigns a 36% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.
What to do: Apply updates per vendor instructions immediately, or discontinue use of the affected component if updates are unavailable, per CISA's required action. Inventory whether the User Activity Video Recording component is installed and whether TCP port 9004 is reachable from user networks, VPNs, or the internet, and restrict that port to trusted hosts as a stopgap. Prioritize remediation given the KEV listing and known ransomware use.
| Netwrix Auditor | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
- Affected
- Netwrix Auditor
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- netwrix
- Products
- auditor
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H