Technical Severity
CRITICALCVSS v3.1 Metrics
9.8
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitation Likelihood
EPSS Prediction
5.85
%
Predictive Probability
Percentile Rank
90.5
th
Documented as more likely to be exploited than 90.5% of known CVEs.
Detection Date
Jul 11, 2023
Remediation Due
Aug 01, 2023
CISA Catalog Active
Threat Analysis
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote attacker to execute code as the NT AUTHORITY\SYSTEM user. Successful exploitation requires that the attacker is able to reach port 9004/TCP, which is commonly blocked by standard enterprise firewalling.
Remediation Directive
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.