EXPOSURES › CVE-2024-12686
CVE-2024-12686
HIGH ⌖ ON CISA KEV · EXPLOITEDBeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection.
This OS command injection flaw lets attackers with existing admin privileges upload malicious files and execute arbitrary OS commands, directly enabling remote code execution within the site user context. For DIB organizations, this represents a critical supply-chain risk where compromised privileged access tools can lead to lateral movement and data exfiltration, requiring immediate patching and strict access controls.
Shame score — A high-severity RCE vulnerability in a widely used privileged access tool that was actively exploited, indicating a failure to patch a known issue before widespread adoption.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.
| PRODUCT | STATUS |
|---|---|
| Secure Remote Access BeyondTrust |
In Process |