Skip to content
COOEY

EXPOSURES › CVE-2022-31199

CVE-2022-31199

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-07-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-31199 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildsupply-chaindata-breachunpatched

Netwrix Auditor's insecure object deserialization flaw allowed unauthenticated remote attackers to execute code as SYSTEM on port 9004.

The Netwrix Auditor User Activity Video Recording component suffered from an insecure object deserialization vulnerability, enabling remote attackers to execute arbitrary code with SYSTEM privileges. This is a critical failure because it directly enables remote code execution (RCE) and was actively exploited in the wild, linking it to ransomware campaigns. DIB organizations must ensure this specific port is blocked and the vendor's patches are applied immediately, as the flaw represents a severe, avoidable security lapse in a compliance-monitoring tool.

Shame score — A critical RCE flaw in a compliance tool was actively exploited in the wild and linked to ransomware, demonstrating severe negligence and a massive breach of trust.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.