PT-2024-10058 · Beyondtrust · Beyondtrust Privileged Remote Access+1

Remmons-R7

·

Published

2024-12-16

·

Updated

2026-05-02

·

CVE-2024-12356

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions prior to 24.3.1 PostgreSQL (affected versions not specified)
Description A critical command injection vulnerability exists in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products. This flaw allows an unauthenticated attacker to inject commands that are executed as a site user. The vulnerability, tracked as CVE-2024-12356, has a CVSS score of 9.8 and is actively exploited in the wild, including in attacks targeting the U.S. Treasury Department attributed to Chinese state-sponsored actors. The vulnerability stems from a failure to properly sanitize input, allowing attackers to execute arbitrary operating system commands. A related zero-day vulnerability was also discovered in PostgreSQL during investigations related to this issue. Approximately 8,600 systems are exposed globally, with a significant concentration in the United States. The vulnerability has been integrated into Patrowl and is being actively exploited. A breach of BeyondTrust's Remote Support SaaS instances occurred, enabling attackers to access an API and reset account passwords.
Recommendations For on-premise systems, upgrade to at least version 22.1.x before applying the patch. Upgrade BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) to version 24.02.001 or later. For cloud-hosted versions, upgrade to version 24.2.1 or later. If patching cannot be applied immediately, disconnect internet-facing appliances from public access. Enforce VPN-only administration. Apply strict IP allowlisting. Deploy Web Application Firewall (WAF) rules to block command injection patterns. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

SQL injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00196
BDU:2025-01601
CVE-2024-12356
RHSA-2025:1720
RHSA-2025:1721
RHSA-2025:1722
RHSA-2025:1723
RHSA-2025:1724
RHSA-2025:1725
RHSA-2025:1726
RHSA-2025:1727
RHSA-2025:1728
RHSA-2025:1729
RHSA-2025:1730
RHSA-2025:1731
RHSA-2025:1732
RHSA-2025:1733
RHSA-2025:1735
RHSA-2025:1736
RHSA-2025:1737
RHSA-2025:1738
RHSA-2025:1739
RHSA-2025:1740
RHSA-2025:1741
RHSA-2025:1742
RHSA-2025:1743
RHSA-2025:1744
RHSA-2025:1745
RHSA-2025:3050
RHSA-2025:3062
RHSA-2025:3063
RHSA-2025:3064
RHSA-2025:3082
RHSA-2025:3978

Affected Products

Beyondtrust Privileged Remote Access
Beyondtrust Remote Support