← Vulnerability feed

Vulnerability record · CVE-2022-31199 · published 8 November 2022

CVE-2022-31199: Netwrix Auditor deserialization flaw allows unauthenticated remote code execution

Netwrix · Auditor

Netwrix Auditor's User Activity Video Recording component contains an insecure deserialization vulnerability (CWE-502) in the protocol it uses, affecting both the Auditor server and agents on monitored systems. An unauthenticated remote attacker can exploit it to run arbitrary code as NT AUTHORITY\SYSTEM, making it a full compromise of the host and any monitored endpoints.

9.8 CVSS 3.1 Critical CISA KEV since 11 Jul 2023 Known ransomware use EPSS 36% · top 1.6% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
36%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network RCE as SYSTEM, listed in CISA KEV with known ransomware use and a public exploit reference.

What it is

Netwrix Auditor's User Activity Video Recording component contains an insecure deserialization vulnerability (CWE-502) in the protocol it uses, affecting both the Auditor server and agents on monitored systems. An unauthenticated remote attacker can exploit it to run arbitrary code as NT AUTHORITY\SYSTEM, making it a full compromise of the host and any monitored endpoints.

Impact

Successful exploitation gives the attacker SYSTEM-level code execution on the Netwrix Auditor server and on agents installed on monitored systems. That level of access enables credential theft, lateral movement, and disabling of monitoring or security controls.

Attack surface

Reachable over the network via the component's underlying protocol (CVSS AV:N), with no authentication (PR:N) and no user interaction (UI:N) required. Any host running the affected server or agent component that is reachable by the attacker is in scope.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2023-07-11 with a due date of 2023-08-01 and flags known ransomware campaign use; EPSS 30-day probability is about 36% (98th percentile), and a public exploit write-up is referenced.

What to do

  • Apply the vendor's update for Netwrix Auditor per vendor instructions; if no update is available, discontinue use of the product as CISA directs.
  • Isolate the Auditor server and agent hosts on a segmented management network with strict firewall rules limiting who can reach the component's protocol ports.
  • Remove or disable the User Activity Video Recording component on hosts where it is not required.
  • Restrict and monitor local administrator and SYSTEM-level activity on Auditor servers and monitored endpoints.
  • Treat monitored systems as potentially compromised and rotate credentials that were accessible from the Auditor server and agents.

Detection

  • Monitor for unexpected processes or child processes spawned by Netwrix Auditor services or agents, especially those running as NT AUTHORITY\SYSTEM.
  • Alert on anomalous network connections to the Auditor component's protocol ports from hosts outside the expected management segment.
  • Review Windows event logs and EDR telemetry for suspicious deserialization-related activity or unusual service behavior on Auditor servers and monitored endpoints.
  • Hunt for post-exploitation indicators such as new services, scheduled tasks, or credential access attempts on Auditor hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-31199 to the Known Exploited Vulnerabilities catalog on 11 July 2023 as "Netwrix Auditor Insecure Object Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 1 August 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31199 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-14969Netwrix auditor incorrect permission assignment vulnerabilityNetwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service …EPSS 0.47%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed9.3CVE-2026-45247Mirasvit Full Page Cache Warmer for Magento 2 PHP object injection RCEMirasvit Full Page Cache Warmer for Magento 2 before 1.11.12 passes the CacheWarmer cookie to PHP's native unserialize() without restriction, allowin…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2022-31199), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.