Junglewise Threat Intelligence

CVE-2024-12686: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

CVE-2024-12686 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2025-01-13

Technologies: BeyondTrust Remote Support (RS), BeyondTrust Privileged Remote Access (PRA). Vendors: BeyondTrust.

Executive brief

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability. An attacker with existing administrative privileges can exploit this to upload malicious files and execute arbitrary operating system commands in the context of the site user.

Affected products

  • BeyondTrust Privileged Remote Access (PRA) up to (including) 24.3.1
  • BeyondTrust Remote Support (RS) up to (including) 24.3.1

Timeline

  • 2024-12-18: disclosed: CVE received from BeyondTrust and published by NVD
  • 2025-01-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-01-13: exploited: Reported as exploited in the wild

Related threats