CVE-2022-31199

CRITICAL(9.8)KEVRansomwareElevated Risk

Netwrix Auditor Insecure Object Deserialization Vulnerability

Description

CVE-2022-31199 is a critical remote code execution vulnerability in the Netwrix Auditor User Activity Video Recording component caused by insecure deserialization of untrusted data (CWE-502). This vulnerability affects both the Netwrix Auditor server and agents installed on monitored systems, potentially allowing an unauthenticated remote attacker to execute arbitrary code as NT AUTHORITY\SYSTEM. The insecure deserialization flaw in Netwrix Auditor's underlying protocol enables complete system compromise without any authentication or user interaction. CISA has added CVE-2022-31199 to its Known Exploited Vulnerabilities catalog and has confirmed its association with ransomware campaigns, making it an urgent remediation priority for organizations using Netwrix Auditor.

KEV Information

Vendor
Netwrix
Product
Auditor
Date Added
July 11, 2023
Due Date
August 1, 2023
Required Action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
netwrixauditor< 10.5

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-502: Deserialization of Untrusted Data

In CVE-2022-31199, the Netwrix Auditor User Activity Video Recording component deserializes data received over its network protocol without adequate validation. This allows an attacker to send specially crafted serialized objects that, upon deserialization, execute arbitrary code on the target system with SYSTEM-level privileges.

Learn more: CWE-502 — Deserialization of Untrusted Data

Impact Analysis

CVE-2022-31199 carries a CRITICAL severity rating with a CVSS v3.1 score of 9.8, the highest tier of risk classification. The vulnerability is remotely exploitable without physical access via a network-based attack vector, and the attack complexity is low, requiring no special conditions for exploitation. Most critically, no authentication is needed and no user interaction is required, meaning the attack can be fully automated against any exposed Netwrix Auditor instance. Successful exploitation delivers high impact across confidentiality, integrity, and availability, granting the attacker code execution as NT AUTHORITY\SYSTEM — the highest privilege level on Windows — across both the Netwrix Auditor server and all monitored agents. This vulnerability has been confirmed for use in ransomware campaigns by CISA, significantly elevating the risk for organizations that have not yet patched. The EPSS score of 5.9% (90th percentile) indicates meaningful exploitation probability.

Exploit Maturity

Public exploit information is available for CVE-2022-31199 via Bishop Fox's advisory, which details the vulnerability discovery and exploitation approach. CISA has confirmed active exploitation in the wild by adding this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 1, 2023. Critically, CISA has also confirmed that CVE-2022-31199 is known to be used in ransomware campaigns, which significantly elevates the threat level. The EPSS score of 5.9% (90th percentile) indicates ongoing exploitation activity against exposed Netwrix Auditor installations.

Remediation

  1. Apply Netwrix Auditor updates immediately as directed by CISA's KEV required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Upgrade to the latest version of Netwrix Auditor that addresses this deserialization vulnerability.
  2. Restrict network access to Netwrix Auditor components by implementing strict firewall rules to limit which systems can communicate with the Netwrix Auditor server and its monitoring agents. Ensure the User Activity Video Recording component's network ports are not exposed to untrusted networks or the internet.
  3. Implement network segmentation to isolate Netwrix Auditor infrastructure from critical business systems, reducing the blast radius if exploitation occurs. Place monitoring agents and the Auditor server in a dedicated management VLAN with restricted access.
  4. Monitor for indicators of compromise including unexpected process execution as NT AUTHORITY\SYSTEM on Netwrix Auditor servers and agents, anomalous network traffic to the Video Recording component's ports, and signs of ransomware activity such as mass file encryption or ransom notes. Review event logs for deserialization-related errors.
  5. Implement deserialization hardening by deploying input validation at the network boundary, enabling .NET deserialization security controls where applicable, and conducting an audit of all Netwrix Auditor components to verify they are running patched versions. Consider deploying intrusion detection signatures specific to this vulnerability.

Technical Details

CVE-2022-31199 is caused by insecure deserialization (CWE-502) in the network protocol used by the Netwrix Auditor User Activity Video Recording component. The component accepts serialized .NET objects over the network and processes them without adequate type validation or integrity checking, allowing an attacker to craft malicious serialized payloads that execute arbitrary code upon deserialization. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects the most dangerous combination of exploitability metrics: the attack is network-based with low complexity, requires no privileges and no user interaction, making it fully automatable against any reachable instance. The code execution occurs in the context of NT AUTHORITY\SYSTEM, meaning the attacker gains the highest possible Windows privilege level on both the central Netwrix Auditor server and any monitored system running the agent, making this vulnerability a prime target for ransomware operators seeking maximum impact across enterprise environments.

Frequently Asked Questions

Is CVE-2022-31199 being actively exploited?

Yes, CVE-2022-31199 is being actively exploited in the wild. CISA has added it to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 1, 2023. CISA has also confirmed that this vulnerability is known to be used in ransomware campaigns, making it a critical priority for immediate remediation.

What products are affected by CVE-2022-31199?

CVE-2022-31199 affects Netwrix Auditor, specifically the User Activity Video Recording component. Both the central Netwrix Auditor server and agents deployed on monitored systems are vulnerable to remote code execution through the insecure deserialization flaw.

How do I fix CVE-2022-31199?

Upgrade Netwrix Auditor to the latest patched version immediately. Restrict network access to the Netwrix Auditor server and agents using firewall rules, and ensure the Video Recording component's ports are not accessible from untrusted networks. See the Remediation section for detailed steps.

How severe is CVE-2022-31199?

CVE-2022-31199 is rated CRITICAL with a CVSS v3.1 score of 9.8 out of 10 — the highest severity tier. It requires no authentication or user interaction for exploitation, and code execution occurs as NT AUTHORITY\SYSTEM. The confirmed use in ransomware campaigns and an EPSS score of 5.9% (90th percentile) further underscore the urgency of remediation.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score36.01%
EPSS Percentile98.3%

Dates

PublishedNovember 8, 2022
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.