peter bassill · operator
$ cve CVE-2022-31199 JSON

CVE-2022-31199 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 36% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2023-08-01.

Description

Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS36.01% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-502
On CISA KEVyes — remediate by 2023-08-01
Public exploitnone known
Published2022-11-08
Last modified2026-06-17

CISA KEV

NameNetwrix Auditor Insecure Object Deserialization Vulnerability
Added2023-07-11
Due2023-08-01
Vendor / productNetwrix / Auditor
Ransomware useknown

Affected (1)

VendorProduct
netwrixauditor

References

→ the Explorer  ·  watch your stack  ·  NVD