CVE-2022-31199
Netwrix Auditor Insecure Object Deserialization Vulnerability
⚠ KEVEPSS 36.0%
Description
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.
How to fix CVE-2022-31199
No package mapping is available — consult the references below for vendor-specific guidance.
Is CVE-2022-31199 being exploited?
Yes — CVE-2022-31199 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (0)
No package mapping in OSV.