CVE-2022-31199: Netwrix Auditor Insecure Object Deserialization Vulnerability

Published Nov 8, 2022
·
Updated

Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.

Other sources

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.

CISA

Affected Software

2 affected components
Netwrix Auditor<10.5
Netwrix Auditor

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Block or restrict access to TCP port 9004 to prevent remote reachability to the Netwrix Auditor User Activity Video Recording component on both Netwrix Auditor servers and agents (e.g., via firewall rules or network ACLs).

  2. Operational

    Discontinue use of Netwrix Auditor if vendor updates are unavailable.

Event History

Nov 8, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Jul 11, 2023
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM

Frequently Asked Questions

1

What is the vulnerability ID for this Netwrix Auditor vulnerability?

The vulnerability ID for this Netwrix Auditor vulnerability is CVE-2022-31199.

2

What is the title of this vulnerability?

The title of this vulnerability is Netwrix Auditor Insecure Object Deserialization Vulnerability.

3

What is the affected software for this vulnerability?

The affected software for this vulnerability is Netwrix Auditor.

4

How does this vulnerability allow an attacker to execute code?

This vulnerability allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user.

5

What is the required condition for successful exploitation of this vulnerability?

Successful exploitation of this vulnerability requires that the attacker is able to reach port 9004/TCP.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203