Vulnerability Intelligence

🛡 CVE-2022-31199

Netwrix Auditor Insecure Object Deserialization Vulnerability
Netwrix Auditor CWE-502 CWE-122

Ransomware use

KNOWN
CISA KEV

EPSS

36.0%
Elevated · 98th pct

Added to KEV

2023-07-11
CISA

Remediate by

2023-08-01
⚠ OVERDUE

CWE

CWE-502 CWE-122
weakness

📈 EPSS exploit probability

36.0%
FIRST EPSS — 30-day probability of exploitation in the wild · band Elevated · higher than 98% of all scored CVEs

⚠ KEV remediation overdue

CISA required federal remediation by 2023-08-01. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.

📄 Description

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation re

🏹 Attributed exploitation

Malware / ransomware (KEV): ransomware (KEV-flagged)

Malware pivots: 🦠 ransomware 🦠 ransomware (KEV-flagged)

🛡 Add to case

Attach CVE-2022-31199 (Vulnerability / CVE) and pull all linked entities:
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php