QID 377863
Date Published: 2023-01-04
QID 377863: Netwrix Auditor Remote Code Execution (RCE) Vulnerability
The Netwrix Auditor application is affected by an insecure object deserialization issue that allows an attacker to execute arbitrary code with the privileges of the affected service. This issue is caused by an unsecured .NET remoting port accessible on TCP port 9004.
Affected Versions:
Netwrix Auditor version prior to 10.5
QID Detection Logic (Authenticated):
The QID checks for vulnerable version of Netwrix Auditor by checking the file version of AuditIntelligence.exe.
An attacker can use this issue to achieve arbitrary code execution on servers running Netwrix Auditor.
Solution
Customers are advised to refer to Netwrix Auditor for information pertaining to this vulnerability.
Vendor References
- Netwrix Auditor -
bishopfox.com/blog/netwrix-auditor-advisory
CVEs related to QID 377863
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Netwrix Auditor |
|