PT-2024-10301 · Beyondtrust · Beyondtrust Privileged Remote Access+1

Published

2024-12-18

·

Updated

2026-02-09

·

CVE-2024-12686

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) (affected versions not specified)
Description A command injection vulnerability has been discovered in BeyondTrust's Privileged Remote Access (PRA) and Remote Support (RS) products. This vulnerability allows an attacker with existing administrative privileges to inject commands and execute them as a site user. The vulnerability is being actively exploited by attackers, and it is recommended to secure systems with the latest patches. The issue is related to the failure to neutralize special elements used in the operating system command, which can allow an attacker to elevate their privileges and execute arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00730
CVE-2024-12686

Affected Products

Beyondtrust Privileged Remote Access
Beyondtrust Remote Support