Lucene search

K
cisa_kevCISACISA-KEV-CVE-2022-31199
HistoryJul 11, 2023 - 12:00 a.m.

Netwrix Auditor Insecure Object Deserialization Vulnerability

2023-07-1100:00:00
CISA
www.cisa.gov
4
netwrix auditor
user activity
video recording
insecure deserialization vulnerability
remote attacker
code execution
nt authority
system user
port 9004/tcp
enterprise firewalling

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.474

Percentile

97.5%

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.474

Percentile

97.5%