Netwrix Auditor Insecure Object Deserialization Vulnerability
Summary
| CVE | CVE-2022-31199 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-08 01:15:00 UTC |
| Updated | 2022-11-09 19:33:00 UTC |
| Description | Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors. |
Risk And Classification
EPSS: 0.360090000 probability, percentile 0.983120000 (date 2026-07-22)
CISA KEV: Listed on 2023-07-11; due 2023-08-01; ransomware use Known
Problem Types: CWE-502
CISA Known Exploited Vulnerability
| Vendor | Netwrix |
|---|---|
| Product | Auditor |
| Name | Netwrix Auditor Insecure Object Deserialization Vulnerability |
| Required Action | Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. |
| Notes | Patch application requires login to customer portal: https://security.netwrix.com/Account/SignIn?ReturnUrl=%2FAdvisories%2FADV-2022-003; https://nvd.nist.gov/vuln/detail/CVE-2022-31199 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Netwrix Auditor Application Critical Vulnerability… | Bishop Fox | MISC | bishopfox.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377863 Netwrix Auditor Remote Code Execution (RCE) Vulnerability