LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-29492: Novi Survey Insecure Deserialization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 13, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 4, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-29492 to its Known Exploited Vulnerabilities catalog on Apr 13, 2023, with a federal patch deadline of May 4, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.

CVE-2023-29492 is an insecure deserialization vulnerability in Novi Survey that allows remote attackers to execute code on the server under the service account context. This matters because successful exploitation can give an attacker full control of the application process, enabling further compromise of the host, data access, or lateral movement depending on how the service is deployed and privileged.

Defenders should treat this as a high-priority remote code execution risk for any environment running Novi Survey until the vendor update is confirmed applied. Specifics such as exact affected versions must be verified against the vendor advisory.

How it works

The weakness is classified as CWE-94 and described as insecure deserialization. In this class of flaw, the application accepts serialized data from an untrusted source and reconstructs objects without sufficient validation. An attacker who can supply crafted input can cause the deserialization process to instantiate unexpected types or invoke methods that lead to arbitrary code execution.

According to the CISA summary, a remote attacker can abuse this to run code on the server in the context of the Novi Survey service account. No further exploit mechanics, payload formats, or preconditions are provided in the available facts; teams should not assume particular attack vectors and must consult the vendor advisory for precise technical details.

Am I affected? How to find it in your systems

Novi Survey is survey software typically deployed as a web application, often on Windows or Linux hosts that expose HTTP/HTTPS endpoints for form creation, response collection, and administration. Inventory efforts should focus on servers and containers running the Novi Survey product, including any related web services or application pools.

Telemetry signs of exploitation for this class of remote code execution include unexpected child processes spawned by the Novi Survey service account, anomalous outbound connections from that account, sudden creation of new files or scheduled tasks, or authentication failures followed by privileged activity. Because no specific indicators of compromise are supplied in the facts, correlate application logs, Windows Security/Sysmon events, or equivalent Linux audit data with the service account identity and escalate any anomalies for forensic review.

How to remediate

The primary remediation is to apply the vendor-supplied updates as directed by CISA: “Apply updates per vendor instructions.” Obtain the official patch or upgraded package from the vendor, test it in a non-production environment if possible, then deploy it to all affected instances. After patching, restart the service and verify the new version is running.

Beyond the patch, harden the deployment for the insecure-deserialization class:

Confirm all version and configuration guidance against the current vendor advisory before declaring systems remediated.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower the likelihood of successful exploitation but do not eliminate the vulnerability; schedule the official update as soon as operationally feasible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to unauthorized access to application data, configuration secrets, or the broader host. Although known ransomware use is not documented for this CVE, treat any confirmed or suspected exploitation as a potential breach. Review access logs, service-account activity, and data stores for signs of exfiltration. As a quick check for personal or organizational email addresses that may appear in known breach corpora, run a free exposure scan of the relevant email addresses against publicly available breach data sets and follow up on any positive hits with password resets and credential hygiene measures.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedNovi Survey · Novi Survey
WeaknessCWE-94
Added to CISA KEVApr 13, 2023
Federal patch deadlineMay 4, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities