ZeroHour

Vulnerabilities

38 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-40139
+3 in the same advisory: …40138 …40140 …40141
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support.

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

NVD description · AI analysis pending
9.2
group max
<1%
  • beyondtrust privileged remote access
  • beyondtrust remote support
CVE-2026-26222
Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmarshalling, allowing remote attackers to read arbitrary files from the underlying system by specifying local file paths. Additionally, attackers can coerce SMB authentication via UNC paths and write arbitrary files to server locations. Because writable paths may be web-accessible under IIS, this can result in unauthenticated remote code execution or denial of service through file overwrite.

NVD description · AI analysis pending
10.0<1%
  • beyond altec doclink
CVE-2026-1731
Pre-Authentication OS Command Injection RCE in BeyondTrust Remote Support and PRA

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical (CVSS 4.0: 9.9) pre-authentication operating system command injection vulnerability (CWE-78). By sending specially crafted requests to the appliance, an unauthenticated remote attacker can execute operating system commands in the context of the site user, gaining code execution without credentials or user interaction. Any organization running RS or PRA appliances that are reachable from the internet, which is their typical deployment mode for remote support and privileged access, is affected. Exploitation is active: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-13 with known ransomware use, carries an EPSS of 89.5% (100th percentile), has a public proof-of-concept, and press coverage links the newly patched BeyondTrust RCE to fast-moving ransomware activity (Storm-1175). BeyondTrust has released fixes, so unpatched, internet-exposed instances should be treated as high-priority compromise targets.

Do: Upgrade all internet-exposed Remote Support and Privileged Remote Access appliances to the fixed releases in BeyondTrust's security advisory immediately, per the CISA KEV required action (apply vendor mitigations or discontinue use if mitigation is unavailable). Until patched, restrict network access to the appliance and review appliance/web logs for suspicious unauthenticated requests, given known ransomware exploitation and the availability of a public proof-of-concept.

9.990% KEV ransomware PoC
  • BeyondTrust Remote Support (RS)
  • BeyondTrust Privileged Remote Access (PRA) Certain older versions (per the CVE description); exact affected and fixed ranges per BeyondTrust's advisory
largeon the order of tens of thousands of internet-exposed RS/PRA appliance instances worldwide
CVE-2025-2297
+1 in the same advisory: …6250
Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user r

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the local user registry under certain conditions. This allows users with the ability to edit their user profile files to elevate their privileges to administrator.

NVD description · AI analysis pending
7.2
group max
<1%
  • beyondtrust privilege management for windows
CVE-2025-5309
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

NVD description · AI analysis pending
8.6<1%
  • beyondtrust privileged remote access
  • beyondtrust remote support
CVE-2025-0217
BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass.

BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A local authenticated attacker can view the connection details of a ShellJump session that was initiated with external tools, allowing unauthorized access to connected sessions.

NVD description · AI analysis pending
7.3<1%
  • beyondtrust privileged remote access
CVE-2025-0889
Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM ob

Prior to 25.2, a local authenticated attacker can elevate privileges on a system with Privilege Management for Windows installed, via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process.

NVD description · AI analysis pending
7.2<1%
  • beyondtrust privilege management for windows
CVE-2024-12686
OS Command Injection in BeyondTrust Privileged Remote Access and Remote Support

CVE-2024-12686 is an OS command injection flaw (CWE-78) in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) that is reachable over the network but requires the attacker to already hold administrative privileges in the product. By injecting commands through an administrative function, the attacker gets arbitrary commands executed on the underlying host as the site user, producing high impact to confidentiality, integrity, and availability in that context. Organizations running BeyondTrust PRA or RS — commonly deployed for privileged remote support and help-desk access — are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-13, confirming exploitation in the wild, and EPSS assigns a 13.8% probability of exploitation within 30 days (96th percentile). The flaw arrives amid a broader wave of BeyondTrust attacks, including the related zero-day CVE-2024-12356 tied to a compromised API key that exposed 17 SaaS customers and was used by a China-linked actor against U.S. Treasury systems, and reported chaining with a PostgreSQL flaw in targeted attacks.

Do: Upgrade all PRA and RS deployments to the fixed releases identified in BeyondTrust's security bulletin for CVE-2024-12686 (including any SaaS instances managed by BeyondTrust), and apply the mitigations required by the CISA KEV entry if patching must be deferred. Because exploitation requires administrative access, review and rotate privileged and API credentials — especially given the related API-key compromise behind CVE-2024-12356 — restrict administrative console exposure to trusted networks, and check logs for unexpected commands executed as the site user.

7.214% KEV
  • BeyondTrust Privileged Remote Access (PRA)
  • BeyondTrust Remote Support (RS)
moderatelikely on the order of thousands of exposed PRA/RS instances (estimate; no install counts in source data)
CVE-2024-12356
Unauthenticated Command Injection in BeyondTrust Privileged Remote Access/Remote Support

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an unauthenticated command injection flaw (CWE-77) that allows a remote attacker to inject commands that are executed as a site user. The vulnerability is network-facing with low attack complexity and requires no privileges or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so any attacker who can reach the affected PRA/RS interface can trigger it. Successful exploitation yields arbitrary command execution in the context of the site user, with high impact ratings for confidentiality, integrity, and availability. Any organization running BeyondTrust PRA or RS — particularly where those remote-access/remote-support services are exposed to the internet — is affected; the available data does not specify affected version ranges. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-19, carries an 88% EPSS probability of exploitation within 30 days (100th percentile), and was reportedly used in the breach of the U.S. Treasury alongside a PostgreSQL vulnerability.

Do: Apply BeyondTrust's patches or vendor-specified mitigations immediately — remediation is mandatory for U.S. federal agencies under the KEV listing, and the source data does not include fixed build numbers, so confirm the correct upgrade version in BeyondTrust's security bulletin. As an interim measure, restrict or remove internet exposure of PRA/RS endpoints and hunt for signs of exploitation (unexpected commands executed as the site user), noting this flaw was used in the U.S. Treasury intrusion. If mitigations are unavailable, CISA's required action is to discontinue use of the product.

9.888% KEV PoC
  • BeyondTrust Privileged Remote Access (PRA)
  • BeyondTrust Remote Support (RS)
moderate≈ a few thousand internet-exposed PRA/RS instances (order-of-magnitude estimate from public internet scans)
CVE-2024-9110
A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.

A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.

NVD description · AI analysis pending
6.1<1%
  • beyondtrust privileged identity
CVE-2024-5813
+1 in the same advisory: …5812
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an informat

A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.

NVD description · AI analysis pending
4.9
group max
<1%
  • beyondtrust beyondinsight password safe
CVE-2024-4219
+1 in the same advisory: …4220
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forge

Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.

NVD description · AI analysis pending
9.1
group max
<1%
  • beyondtrust beyondinsight
CVE-2024-4018
+1 in the same advisory: …4017
Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This

Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 before 4.0.3.

NVD description · AI analysis pending
7.8<1%
  • beyondtrust u-series appliance
CVE-2024-25083
+1 in the same advisory: …1591
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1.

An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiates a repair, there is an attack vector through which the user is able to execute any program with elevated privileges.

NVD description · AI analysis pending
7.8
group max
<1%
  • beyondtrust privilege management for windows
CVE-2023-49944
The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by de

The Challenge Response feature of BeyondTrust Privilege Management for Windows (PMfW) before 2023-07-14 allows local administrators to bypass this feature by decrypting the shared key, or by locating the decrypted shared key in process memory. The threat is mitigated by the Agent Protection feature.

NVD description · AI analysis pending
6.7<1%
  • beyondtrust privilege management for windows
CVE-2020-12612
+3 in the same advisory: …28369 …12615 …12614
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When specifying a program to elevate, it can typically be found within the Program Files (x86) folder and therefore uses the %ProgramFiles(x86)% environment variable. However, when this same policy gets pushed to a 32bit machine, this environment variable does not exist. Therefore, since the standard user can create a user level environment variable, they can repoint this variable to any folder the user has full control of. Then, the folder structure can be created in such a way that a rule matches and arbitrary code runs elevated.

NVD description · AI analysis pending
7.8<1%
  • beyondtrust privilege management for windows
CVE-2021-3187
An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7.

An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can elevate privileges by running a malicious script (that executes as root from a temporary directory) during install time. (This applies to macOS before 10.15.5, or Security Update 2020-003 on Mojave and High Sierra, Later versions of macOS are not vulnerable.)

NVD description · AI analysis pending
8.8<1%
  • beyondtrust privilege management for mac
CVE-2020-12613
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6.

An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. An attacker can spawn a process with multiple users as part of the security token (prior to Avecto elevation). When Avecto elevates the process, it removes the user who is launching the process, but not the second user. Therefore this second user still retains access and can give permission to the process back to the first user.

NVD description · AI analysis pending
8.8<1%
  • beyondtrust privilege management for windows
CVE-2023-23632
BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass.

BeyondTrust Privileged Remote Access (PRA) versions 22.2.x to 22.4.x are vulnerable to a local authentication bypass. Attackers can exploit a flawed secret verification process in the BYOT shell jump sessions, allowing unauthorized access to jump items by guessing only the first character of the secret.

NVD description · AI analysis pending
7.8<1%
  • beyondtrust privileged remote access
CVE-2023-4310
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited t

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be exploited through a malicious HTTP request. Successful exploitation of this vulnerability can allow an unauthenticated remote attacker to execute underlying operating system commands within the context of the site user. This issue is fixed in version 23.2.3.

NVD description · AI analysis pending
9.82%
  • beyondtrust privileged remote access
  • beyondtrust remote support
CVE-2021-31589
A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which all

A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Software version 6.0.1 and older, which allows the injection of unauthenticated, specially-crafted web requests without proper sanitization.

NVD description · AI analysis pending
6.129% PoC ×2
  • beyondtrust appliance base software
CVE-2021-42254
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.

BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.

NVD description · AI analysis pending
7.8<1%
  • beyondtrust privilege management for windows
CVE-2021-3156
Heap-Based Buffer Overflow in Sudo Enables Local Privilege Escalation (CVE-2021-3156)

CVE-2021-3156 is an off-by-one error (CWE-193) in the Unix Sudo utility that causes a heap-based buffer overflow (CWE-122) in Sudo's handling of command-line arguments. It is triggered locally when an unprivileged user invokes Sudo with specially crafted arguments, requiring no special privileges or non-default configuration. A successful exploit allows the attacker to execute arbitrary code as root, achieving full local privilege escalation on the host. Any Linux, Unix, or other system running a vulnerable version of Sudo is affected, and because Sudo ships by default on virtually all such systems the potential footprint is enormous. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-06) and carries a 100% EPSS probability of exploitation within 30 days, indicating active in-the-wild exploitation, though specific ransomware use is unknown.

Do: Upgrade Sudo to a patched release (1.9.5p2 or later, or the vendor-supplied update for your distribution) per vendor instructions, as required by the CISA KEV listing. Audit all Unix-like hosts by checking the installed Sudo version through your package manager and prioritize patching multi-user and internet-facing servers. Restricting local shell access and monitoring for anomalous Sudo invocations can reduce risk while patching completes.

7.8100% KEV PoC ×12
  • Sudo Version range not specified in source data; publicly documented affected range is Sudo 1.8.2 through 1.9.5p1, fixed in 1.9.5p2
masstens of millions of Linux/Unix servers, workstations and devices (Sudo is preinstalled on virtually all Linux distributions)
CVE-2020-9326
BeyondTrust Privilege Management for Windows and Mac (aka PMWM;

BeyondTrust Privilege Management for Windows and Mac (aka PMWM; formerly Avecto Defendpoint) 5.1 through 5.5 before 5.5 SR1 mishandles command-line arguments with PowerShell .ps1 file extensions present, leading to a DefendpointService.exe crash.

NVD description · AI analysis pending
7.51%
  • beyondtrust privilege management for windows and mac
CVE-2018-10959
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigg

Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.

NVD description · AI analysis pending
7.52%
  • beyondtrust avecto defendpoint
CVE-2018-13471
The mintToken function of a smart contract implementation for BeyondCashToken, an Ethereum token, has an integer overflow that allows the owner of the contract

The mintToken function of a smart contract implementation for BeyondCashToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

NVD description · AI analysis pending
7.51% PoC
  • beyondcash beyondcashtoken
CVE-2017-5996
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\Progr

The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.

NVD description · AI analysis pending
7.81%
  • beyondtrust remote support