CVE-2022-31199
Description
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
Summary dbcve.org
Unauthenticated remote code execution vulnerability in the Netwrix Auditor User Activity Video Recording component exists within the protocol used between the Netwrix Auditor server and its agents. The flaw can be triggered remotely without authentication and allows arbitrary code execution as NT AUTHORITY\SYSTEM on the Netwrix Auditor server as well as on monitored endpoints hosting an agent.
Mitigation
Apply the vendor-supplied patch for the Netwrix Auditor User Activity Video Recording component on both the central server and all monitored agents immediately; until patched, restrict network exposure of the affected service/protocol to trusted networks and monitor for anomalous activity.