CVE-2022-31199
Netwrix Auditor Insecure Object Deserialization Vulnerability
Description
CVE-2022-31199 is a critical remote code execution vulnerability in the Netwrix Auditor User Activity Video Recording component caused by insecure deserialization of untrusted data (CWE-502). This vulnerability affects both the Netwrix Auditor server and agents installed on monitored systems, potentially allowing an unauthenticated remote attacker to execute arbitrary code as NT AUTHORITY\SYSTEM. The insecure deserialization flaw in Netwrix Auditor's underlying protocol enables complete system compromise without any authentication or user interaction. CISA has added CVE-2022-31199 to its Known Exploited Vulnerabilities catalog and has confirmed its association with ransomware campaigns, making it an urgent remediation priority for organizations using Netwrix Auditor.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| netwrix | auditor | < 10.5 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- https://bishopfox.com/blog/netwrix-auditor-advisory(Exploit, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-31199(US Government Resource)
Weakness Type
CWE-502: Deserialization of Untrusted Data
In CVE-2022-31199, the Netwrix Auditor User Activity Video Recording component deserializes data received over its network protocol without adequate validation. This allows an attacker to send specially crafted serialized objects that, upon deserialization, execute arbitrary code on the target system with SYSTEM-level privileges.
Learn more: CWE-502 — Deserialization of Untrusted Data
Impact Analysis
CVE-2022-31199 carries a CRITICAL severity rating with a CVSS v3.1 score of 9.8, the highest tier of risk classification. The vulnerability is remotely exploitable without physical access via a network-based attack vector, and the attack complexity is low, requiring no special conditions for exploitation. Most critically, no authentication is needed and no user interaction is required, meaning the attack can be fully automated against any exposed Netwrix Auditor instance. Successful exploitation delivers high impact across confidentiality, integrity, and availability, granting the attacker code execution as NT AUTHORITY\SYSTEM — the highest privilege level on Windows — across both the Netwrix Auditor server and all monitored agents. This vulnerability has been confirmed for use in ransomware campaigns by CISA, significantly elevating the risk for organizations that have not yet patched. The EPSS score of 5.9% (90th percentile) indicates meaningful exploitation probability.
Exploit Maturity
Public exploit information is available for CVE-2022-31199 via Bishop Fox's advisory, which details the vulnerability discovery and exploitation approach. CISA has confirmed active exploitation in the wild by adding this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 1, 2023. Critically, CISA has also confirmed that CVE-2022-31199 is known to be used in ransomware campaigns, which significantly elevates the threat level. The EPSS score of 5.9% (90th percentile) indicates ongoing exploitation activity against exposed Netwrix Auditor installations.
Remediation
- Apply Netwrix Auditor updates immediately as directed by CISA's KEV required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Upgrade to the latest version of Netwrix Auditor that addresses this deserialization vulnerability.
- Restrict network access to Netwrix Auditor components by implementing strict firewall rules to limit which systems can communicate with the Netwrix Auditor server and its monitoring agents. Ensure the User Activity Video Recording component's network ports are not exposed to untrusted networks or the internet.
- Implement network segmentation to isolate Netwrix Auditor infrastructure from critical business systems, reducing the blast radius if exploitation occurs. Place monitoring agents and the Auditor server in a dedicated management VLAN with restricted access.
- Monitor for indicators of compromise including unexpected process execution as NT AUTHORITY\SYSTEM on Netwrix Auditor servers and agents, anomalous network traffic to the Video Recording component's ports, and signs of ransomware activity such as mass file encryption or ransom notes. Review event logs for deserialization-related errors.
- Implement deserialization hardening by deploying input validation at the network boundary, enabling .NET deserialization security controls where applicable, and conducting an audit of all Netwrix Auditor components to verify they are running patched versions. Consider deploying intrusion detection signatures specific to this vulnerability.
Technical Details
CVE-2022-31199 is caused by insecure deserialization (CWE-502) in the network protocol used by the Netwrix Auditor User Activity Video Recording component. The component accepts serialized .NET objects over the network and processes them without adequate type validation or integrity checking, allowing an attacker to craft malicious serialized payloads that execute arbitrary code upon deserialization. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects the most dangerous combination of exploitability metrics: the attack is network-based with low complexity, requires no privileges and no user interaction, making it fully automatable against any reachable instance. The code execution occurs in the context of NT AUTHORITY\SYSTEM, meaning the attacker gains the highest possible Windows privilege level on both the central Netwrix Auditor server and any monitored system running the agent, making this vulnerability a prime target for ransomware operators seeking maximum impact across enterprise environments.
Frequently Asked Questions
Is CVE-2022-31199 being actively exploited?
Yes, CVE-2022-31199 is being actively exploited in the wild. CISA has added it to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 1, 2023. CISA has also confirmed that this vulnerability is known to be used in ransomware campaigns, making it a critical priority for immediate remediation.
What products are affected by CVE-2022-31199?
CVE-2022-31199 affects Netwrix Auditor, specifically the User Activity Video Recording component. Both the central Netwrix Auditor server and agents deployed on monitored systems are vulnerable to remote code execution through the insecure deserialization flaw.
How do I fix CVE-2022-31199?
Upgrade Netwrix Auditor to the latest patched version immediately. Restrict network access to the Netwrix Auditor server and agents using firewall rules, and ensure the Video Recording component's ports are not accessible from untrusted networks. See the Remediation section for detailed steps.
How severe is CVE-2022-31199?
CVE-2022-31199 is rated CRITICAL with a CVSS v3.1 score of 9.8 out of 10 — the highest severity tier. It requires no authentication or user interaction for exploitation, and code execution occurs as NT AUTHORITY\SYSTEM. The confirmed use in ransomware campaigns and an EPSS score of 5.9% (90th percentile) further underscore the urgency of remediation.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.