CVE-2022-31199: Netwrix Auditor
EPSS36.0%No. 963 of 1739 in KEV
CVE year2022~1 yrs before listing
Same vendor in KEV1
Same product1
| Field | Value |
|---|---|
| Vendor | Netwrix |
| Product | Auditor |
| Name | Netwrix Auditor Insecure Object Deserialization Vulnerability |
| Added to KEV | 2023-07-11 |
| US federal due date | 2023-08-01 |
| Ransomware use | Known |
| CWE | CWE-502, CWE-122 |
CISA description
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Netwrix Auditor vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11.