Skip to content
COOEY

EXPOSURES › CVE-2024-12356

CVE-2024-12356

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-19 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-12356 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildsupply-chain

BeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection.

This unauthenticated command injection vulnerability enables remote code execution as a site user, posing a severe risk to DIB organizations relying on BeyondTrust for privileged access. The vulnerability is actively exploited in the wild, requiring immediate patching and network segmentation to prevent lateral movement and data exfiltration.

Shame score — An unauthenticated RCE vulnerability in a critical remote access product that is actively being exploited in the wild represents a severe, avoidable security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Secure Remote Access
BeyondTrust
In Process