CRITICAL

CVE-2022-31199

Netwrix Auditor 2022-11-08 CVSS v3.1
CVSS
9.8
KEV

Description

Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.

Summary dbcve.org

Unauthenticated remote code execution vulnerability in the Netwrix Auditor User Activity Video Recording component exists within the protocol used between the Netwrix Auditor server and its agents. The flaw can be triggered remotely without authentication and allows arbitrary code execution as NT AUTHORITY\SYSTEM on the Netwrix Auditor server as well as on monitored endpoints hosting an agent.

Mitigation

Apply the vendor-supplied patch for the Netwrix Auditor User Activity Video Recording component on both the central server and all monitored agents immediately; until patched, restrict network exposure of the affected service/protocol to trusted networks and monitor for anomalous activity.

Proof of Concept

Weakness (CWE)

CWE-502 Deserialization of Untrusted Data

EPSS Score

36.01%
Probability of exploitation in next 30 days
98.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE