Vulnerability record · CVE-2022-31199 · published 8 November 2022
CVE-2022-31199: Netwrix Auditor deserialization flaw allows unauthenticated remote code execution
Netwrix · Auditor
Netwrix Auditor's User Activity Video Recording component contains an insecure deserialization vulnerability (CWE-502) in the protocol it uses, affecting both the Auditor server and agents on monitored systems. An unauthenticated remote attacker can exploit it to run arbitrary code as NT AUTHORITY\SYSTEM, making it a full compromise of the host and any monitored endpoints.
Description
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 unauthenticated network RCE as SYSTEM, listed in CISA KEV with known ransomware use and a public exploit reference.
What it is
Netwrix Auditor's User Activity Video Recording component contains an insecure deserialization vulnerability (CWE-502) in the protocol it uses, affecting both the Auditor server and agents on monitored systems. An unauthenticated remote attacker can exploit it to run arbitrary code as NT AUTHORITY\SYSTEM, making it a full compromise of the host and any monitored endpoints.
Impact
Successful exploitation gives the attacker SYSTEM-level code execution on the Netwrix Auditor server and on agents installed on monitored systems. That level of access enables credential theft, lateral movement, and disabling of monitoring or security controls.
Attack surface
Reachable over the network via the component's underlying protocol (CVSS AV:N), with no authentication (PR:N) and no user interaction (UI:N) required. Any host running the affected server or agent component that is reachable by the attacker is in scope.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2023-07-11 with a due date of 2023-08-01 and flags known ransomware campaign use; EPSS 30-day probability is about 36% (98th percentile), and a public exploit write-up is referenced.
What to do
- Apply the vendor's update for Netwrix Auditor per vendor instructions; if no update is available, discontinue use of the product as CISA directs.
- Isolate the Auditor server and agent hosts on a segmented management network with strict firewall rules limiting who can reach the component's protocol ports.
- Remove or disable the User Activity Video Recording component on hosts where it is not required.
- Restrict and monitor local administrator and SYSTEM-level activity on Auditor servers and monitored endpoints.
- Treat monitored systems as potentially compromised and rotate credentials that were accessible from the Auditor server and agents.
Detection
- Monitor for unexpected processes or child processes spawned by Netwrix Auditor services or agents, especially those running as NT AUTHORITY\SYSTEM.
- Alert on anomalous network connections to the Auditor component's protocol ports from hosts outside the expected management segment.
- Review Windows event logs and EDR telemetry for suspicious deserialization-related activity or unusual service behavior on Auditor servers and monitored endpoints.
- Hunt for post-exploitation indicators such as new services, scheduled tasks, or credential access attempts on Auditor hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-31199 to the Known Exploited Vulnerabilities catalog on 11 July 2023 as "Netwrix Auditor Insecure Object Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 1 August 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bishopfox.com/blog/netwrix-auditor-advisory | ExploitThird Party Advisory |
| https://bishopfox.com/blog/netwrix-auditor-advisory | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-31199 | US Government Resource |
Track CVE-2022-31199 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-31199), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.