Executive Summary
Netwrix identified a vulnerability in Netwrix Auditor for Exchange during routine internal review, and external penetration testing identified a vulnerability in the Netwrix Auditor User Activity Core Service Agent. The Exchange-related vulnerability affects audit data collection functionality and may allow an attacker with privileged access to the Exchange server to execute code in the context of the affected Netwrix Auditor Data Collector Service. The User Activity Core Service Agent vulnerability relates to insufficient authorization checks on the agent’s local service interface, which may allow an authenticated, low-privileged local user to access functionality intended to be restricted to higher-privileged operations.
All Netwrix Auditor customers are advised to apply the available update as soon as possible. Netwrix is unaware of any current exploitation of these vulnerabilities.
Vulnerability
Deserialization of Untrusted Data
| Affected Component | Affected Versions | CVSS 4.0 Score | CVSS 3.1 Score (Base / Temporal) |
|---|---|---|---|
| Netwrix Auditor for Exchange | <10.8.15840 & <10.9.16393 | 8.6 | 7.2 / 6.3 |
Netwrix Auditor does not sufficiently restrict how certain Exchange audit data is processed during data collection. An attacker with administrative access to the Exchange server may, under specific conditions, be able to execute code in the context of the affected Netwrix Auditor service.
Missing Authorization in User Activity Core Service Agent
| Affected Component | Affected Versions | CVSS 4.0 Score | CVSS 3.1 Score (Base / Temporal) |
|---|---|---|---|
| Netwrix Auditor User Activity Core Service Agent | <10.8.15840 & <10.9.16393 | 7.0 | 7.1 / 6.4 |
Netwrix Auditor User Activity Core Service Agent does not perform sufficient authorization checks on requests made to its local service interface. This may allow an authenticated, low-privileged local user to access functionality intended to be restricted to higher-privileged operations, potentially resulting in unauthorized access to session data or a reduction in the reliability of audit data collection.
Exploitability
Factors such as whether details about the vulnerability are publicly known, whether an exploit is readily available, or whether adversaries are actively exploiting the vulnerability are valuable in making risk-based judgments about urgency and priority; customers should use the information below in making those decisions.
| Title | Publicly known? | Exploit available? | Actively exploited? |
|---|---|---|---|
| Deserialization of Untrusted Data | No | No | No |
| Missing Authorization in User Activity Core Service Agent | No | No | No |
Solution
All Netwrix Auditor customers are advised to update Netwrix Auditor as soon as possible:
- 10.8: Update to version 10.8.15840 or later
- 10.9: Update to version 10.9.16393 or later
Instructions for the Netwrix Auditor upgrade process can be found in this documentation.
Please contact the Netwrix technical support team should you need assistance.
Official Fixes
Updated software has been released containing an official fix for the vulnerability as indicated in the table below.
| Product | Release Version |
|---|---|
| Netwrix Auditor 10.8 | 10.8.15840 |
| Netwrix Auditor 10.9 | 10.9.16393 |
FAQ
-
How do I determine my current version of Netwrix Auditor?
The version can be found in the General tab in Netwrix Auditor and in Windows “Add/Remove Programs”.
-
Are there any configuration changes required after updating?
No additional configuration changes are required beyond applying the update to the remediated version or later.
Revisions
Updates to this advisory may be made as necessary. Information about each change will be published in the table below.
| Revision | Date | Description |
|---|---|---|
| 1 | 2026-07-16T12:00:00Z | First published |
| 2 | 2026-07-17T12:00:00Z | Added additional UAVR Service vulnerability information. |
Disclaimer
The information and materials included in or linked to this Security Advisory are provided on an “as-is” basis and without warranty of any kind, and we disclaim all representations and warranties of any kind, whether express or implied, including warranties of merchantability and fitness for a particular use. You acknowledge and agree that your use of the information and materials included in or linked to this Security Advisory are at your own risk.