Skip to content
COOEY

EXPOSURES › CVE-2024-12686

CVE-2024-12686

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-01-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-12686 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildsupply-chainunpatched

BeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection.

This OS command injection flaw lets attackers with existing admin privileges upload malicious files and execute arbitrary OS commands, directly enabling remote code execution within the site user context. For DIB organizations, this represents a critical supply-chain risk where compromised privileged access tools can lead to lateral movement and data exfiltration, requiring immediate patching and strict access controls.

Shame score — A high-severity RCE vulnerability in a widely used privileged access tool that was actively exploited, indicating a failure to patch a known issue before widespread adoption.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Secure Remote Access
BeyondTrust
In Process