BeyondTrust fixes critical vulnerability in remote access, support solutions (CVE-2024-12356)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-12356 | Unauthenticated Command Injection in BeyondTrust Privileged Remote Access/Remote Support BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an unauthenticated command injection flaw (CWE-77) that allows a remote attacker to inject commands that are executed as a site user. The vulnerability is network-facing with low attack complexity and requires no privileges or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so any attacker who can reach the affected PRA/RS interface can trigger it. Successful exploitation yields arbitrary command execution in the context of the site user, with high impact ratings for confidentiality, integrity, and availability. Any organization running BeyondTrust PRA or RS — particularly where those remote-access/remote-support services are exposed to the internet — is affected; the available data does not specify affected version ranges. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-19, carries an 88% EPSS probability of exploitation within 30 days (100th percentile), and was reportedly used in the breach of the U.S. Treasury alongside a PostgreSQL vulnerability. Do: Apply BeyondTrust's patches or vendor-specified mitigations immediately — remediation is mandatory for U.S. federal agencies under the KEV listing, and the source data does not include fixed build numbers, so confirm the correct upgrade version in BeyondTrust's security bulletin. As an interim measure, restrict or remove internet exposure of PRA/RS endpoints and hunt for signs of exploitation (unexpected commands executed as the site user), noting this flaw was used in the U.S. Treasury intrusion. If mitigations are unavailable, CISA's required action is to discontinue use of the product. | 9.8 | 88% | KEV PoC |
| moderate≈ a few thousand internet-exposed PRA/RS instances (order-of-magnitude estimate from public internet scans) | |
| CVE-2024-12686 | OS Command Injection in BeyondTrust Privileged Remote Access and Remote Support CVE-2024-12686 is an OS command injection flaw (CWE-78) in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) that is reachable over the network but requires the attacker to already hold administrative privileges in the product. By injecting commands through an administrative function, the attacker gets arbitrary commands executed on the underlying host as the site user, producing high impact to confidentiality, integrity, and availability in that context. Organizations running BeyondTrust PRA or RS — commonly deployed for privileged remote support and help-desk access — are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-13, confirming exploitation in the wild, and EPSS assigns a 13.8% probability of exploitation within 30 days (96th percentile). The flaw arrives amid a broader wave of BeyondTrust attacks, including the related zero-day CVE-2024-12356 tied to a compromised API key that exposed 17 SaaS customers and was used by a China-linked actor against U.S. Treasury systems, and reported chaining with a PostgreSQL flaw in targeted attacks. Do: Upgrade all PRA and RS deployments to the fixed releases identified in BeyondTrust's security bulletin for CVE-2024-12686 (including any SaaS instances managed by BeyondTrust), and apply the mitigations required by the CISA KEV entry if patching must be deferred. Because exploitation requires administrative access, review and rotate privileged and API credentials — especially given the related API-key compromise behind CVE-2024-12356 — restrict administrative console exposure to trusted networks, and check logs for unexpected commands executed as the site user. | 7.2 | 14% | KEV |
| moderatelikely on the order of thousands of exposed PRA/RS instances (estimate; no install counts in source data) |
Full article641 words · extracted from helpnetsecurity.com · click to collapse
BeyondTrust has fixed an unauthenticated command injection vulnerability (CVE-2024-12356) in its Privileged Remote Access (PRA) and Remote Support (RS) products that may allow remote code execution, and is urging organizations with on-premise installations to test the patch and implement it quickly.

About CVE-2024-12356
BeyondTrust Privileged Remote Access is an enterprise solution that mediates secure remote access to enterprise environments for employees and trusted vendors. BeyondTrust Remote Support allows organizations’ IT helpdesk personnel to securely connect to and provide support for remote systems.
CVE-2024-12356 is a command injection vulnerability stemming from the improper neutralization of special elements used in commands. It can be triggered via a malicious client request, and may allow unauthenticated remote attackers to execute underlying operating system commands within the context of the site user.
No privileges and no user interaction is required for a successful exploitation, and the complexity of the attack is deemed to be “low”.
BeyondTrust has confirmed that the vulnerability affects all versions of the two software solutions, up until and including v24.3.1.
“A patch has been applied to all RS/PRA cloud customers as of December 16, 2024 that remediates this vulnerability,” the company said.
“On-premise customers of RS/PRA should apply the patch if their instance is not subscribed to automatic updates in their /appliance interface. If customers are on a version older than 22.1, they will need to upgrade in order to apply this patch.”
No alternative mitigations or workarounds are available.
UPDATE (December 19, 2024, 05:30 a.m. ET):
BeyondTrust has released patches for another command injection vulnerability (CVE-2024-12686) in PRA/RS.
Security advisories for the two vulnerabilities don’t say how the flaws were discovered, but a separate report mentions them having been identified during a forensics investigation into a recent security incident.
“Potentially anomalous behavior was detected by our Information Security team on December 2nd, 2024, tied to one customer instance of Remote Support SaaS, and the team immediately commenced an investigation,” the company said.
On December 5th, the team confirmed that the anomalous behavior impacted a “limited number” of instances of Remote Support SaaS, which were then suspended and quarantined for forensic analysis.
Affected customers were notified, provided with alternative TS SaaS instances, and a compromised Remote Support SaaS API key was identified and revoked.
“We continue to pursue all possible paths as part of the forensic analysis, including our work with external forensic parties, to ensure we conduct as thorough an investigation as possible. We also continue to communicate and work closely with all known affected customers and will provide updates here until our investigation is concluded,” the company stated on Wednesday.
Whether the two discovered vulnerabilities have been exploited to compromise customers or were merely unearthed during this investigation is unclear. We’ve reached out to BeyondTrust for clarification, and we’ll update this article if we hear back from them.
UPDATE (December 19, 2024, 03:50 p.m. ET):
Unfortunately, BeyondTrust is seemingly not ready to answer specific questions about the discovered vulnerabilities.
“Our investigation is ongoing, and we are continuing to work with independent third-party cybersecurity firms to conduct a thorough investigation. At this time, BeyondTrust is focused on ensuring that all customer instances—both cloud and self-hosted—are fully updated and secure,” a company spokesperson told Help Net Security.
“Our priority remains supporting the limited number of customers impacted and safeguarding their environments. We will continue to provide regular updates via our website as our investigation progresses.”
But CISA has added CVE-2024-12356 to its Known Exploited Vulnerabilities catalog, so it seems likely that this incident involved its exploitation.
Affected users with deployments in the cloud have been notified by the company, while those with on-prem installations would do well to check for the presence of indicators of compromise BeyondTrust has previously shared.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/12/18/beyondtrust-fixes-critical-vulnerability-in-remote-access-support-solutions-cve-2024-12356/