CVE-2024-12356
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 27 December 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 87.99% probability · 100th percentile
- CISA KEV
- Listed 19 December 2024 · due 27 December 2024
- Weakness
- CWE-77
- Affected
- beyondtrust/privileged remote access · beyondtrust/remote support
- Source
- 13061848-ea10-403d-bd75-c83a022c2891
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 ; https://nvd.nist.gov/vuln/detail/CVE-2024-12356
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-12356Third Party Advisory, US Government Resource
- https://www.beyondtrust.com/trust-center/security-advisories/bt24-10Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-12356Third Party Advisory, US Government Resource
- https://attackerkb.com/topics/G5s8ZWAbYH/cve-2024-12356/rapid7-analysisExploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-12356US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.