EXPOSURES › CVE-2024-12356
CVE-2024-12356
HIGH ⌖ ON CISA KEV · EXPLOITEDBeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection.
This unauthenticated command injection vulnerability enables remote code execution as a site user, posing a severe risk to DIB organizations relying on BeyondTrust for privileged access. The vulnerability is actively exploited in the wild, requiring immediate patching and network segmentation to prevent lateral movement and data exfiltration.
Shame score — An unauthenticated RCE vulnerability in a critical remote access product that is actively being exploited in the wild represents a severe, avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.
| PRODUCT | STATUS |
|---|---|
| Secure Remote Access BeyondTrust |
In Process |