216.73.217.22

CVE-2022-31199

· Published 11/07/2023 02:00 · Modified 20/12/2025 23:03 · Author: Cybersecurity and Infrastructure Security Agency

Labels: CVE-2022-31199

Essential information

Published
11/07/2023 02:00
Modified
20/12/2025 23:03
Author
Cybersecurity and Infrastructure Security Agency
Creator
Cybersecurity and Infrastructure Security Agency
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
Yes
CWE
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.

NVD status

NVD
View on NVD