🛡 CVE-2022-31199
Netwrix Auditor Insecure Object Deserialization Vulnerability
Netwrix Auditor CWE-502 CWE-122
Ransomware use
KNOWN
CISA KEV
EPSS
36.0%
Elevated · 98th pct
Added to KEV
2023-07-11
CISA
Remediate by
2023-08-01
⚠ OVERDUE
CWE
CWE-502 CWE-122
weakness
📈 EPSS exploit probability
36.0%
FIRST EPSS — 30-day probability of exploitation in the wild · band Elevated · higher than 98% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2023-08-01. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation re
🏹 Attributed exploitation
Malware / ransomware (KEV): ransomware (KEV-flagged)
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron