• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new netwrix auditor bug could let attackers compromise active directory

New Netwrix Auditor Bug Could Let Attackers Compromise Active Directory Domain

You are here: Home / General Cyber Security News / New Netwrix Auditor Bug Could Let Attackers Compromise Active Directory Domain
July 16, 2022

Researchers have disclosed particulars about a security vulnerability in the Netwrix Auditor software that, if properly exploited, could lead to arbitrary code execution on afflicted devices.

“Because this assistance is typically executed with substantial privileges in an Energetic Directory natural environment, the attacker would most likely be in a position to compromise the Lively Directory area,” Bishop Fox said in an advisory posted this 7 days.

Auditor is an auditing and visibility platform that enables businesses to have a consolidated perspective of their IT environments, including Active Directory, Trade, file servers, SharePoint, VMware, and other systems—all from a single console.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Netwrix, the firm at the rear of the software program, statements extra than 11,500 shoppers throughout about 100 international locations, this kind of as Airbus, Virgin, King’s Faculty Healthcare facility, and Credissimo, between other people.

Netwrix Auditor Bug

The flaw, which impacts all supported variations prior to 10.5, has been described as an insecure object deserialization, which happens when untrusted user-controllable facts is parsed to inflict remote code execution attacks.

CyberSecurity

The root bring about of the bug is an unsecured .NET remoting support which is accessible on TCP port 9004 on the Netwrix server, enabling an actor to execute arbitrary instructions on the server.

“Given that the command was executed with NT AUTHORITYSYSTEM privileges, exploiting this issue would enable an attacker to entirely compromise the Netwrix server,” Bishop Fox’s Jordan Parkin stated.

Companies relying on Auditor are encouraged to update the application to the hottest variation, 10.5, released on June 6, to thwart any likely hazards.

Discovered this post fascinating? Follow THN on Facebook, Twitter  and LinkedIn to study a lot more distinctive content material we write-up.


Some parts of this post are sourced from:
thehackernews.com

Previous Post: «Cyber Security News Average American Accesses Suspicious Sites 6.5 Times a Day
Next Post: Hackers Targeting VoIP Servers By Exploiting Digium Phone Software hackers targeting voip servers by exploiting digium phone software»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.