CVE-2022-31199: Netwrix Auditor Insecure Object Deserialization Vulnerability
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
Other sources
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Block or restrict access to TCP port 9004 to prevent remote reachability to the Netwrix Auditor User Activity Video Recording component on both Netwrix Auditor servers and agents (e.g., via firewall rules or network ACLs).
- Operational
Discontinue use of Netwrix Auditor if vendor updates are unavailable.
Event History
Frequently Asked Questions
What is the vulnerability ID for this Netwrix Auditor vulnerability?
The vulnerability ID for this Netwrix Auditor vulnerability is CVE-2022-31199.
What is the title of this vulnerability?
The title of this vulnerability is Netwrix Auditor Insecure Object Deserialization Vulnerability.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Netwrix Auditor.
How does this vulnerability allow an attacker to execute code?
This vulnerability allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user.
What is the required condition for successful exploitation of this vulnerability?
Successful exploitation of this vulnerability requires that the attacker is able to reach port 9004/TCP.