ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Adds Second BeyondTrust Flaw to KEV Catalog Amid Active Attacks

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-12686CVE-2024-12356CVE-2023-48365

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-48365
HTTP Request Smuggling/Tunneling in Qlik Sense Allows Privilege Escalation

Qlik Sense contains an HTTP tunneling flaw (CWE-444, inconsistent interpretation of HTTP requests, i.e., HTTP request smuggling) in which the application's tunneling component and the backend server hosting the software disagree about HTTP request boundaries. An attacker triggers it by sending crafted HTTP requests through the tunneling mechanism of an affected Qlik Sense deployment. Exploitation lets the attacker escalate privileges and execute HTTP requests against the backend server, reaching internal services and interfaces that should only be accessible to the application. Any organization running an affected Qlik Sense deployment is exposed, with internet-facing instances at greatest risk. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-01-13 with ransomware use known, and EPSS assigns a 24.7% probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Apply Qlik's remediation for CVE-2023-48365 per the vendor's security instructions, or discontinue use of the product if mitigations are unavailable (CISA KEV required action). Prioritize internet-exposed Qlik Sense servers, and given known ransomware use, hunt for indicators such as unexpected requests arriving at the backend server, anomalous authentication activity, and lateral movement originating from the Qlik host.

9.924% KEV ransomware
  • Qlik Sense
large≈tens of thousands of enterprise deployments, with on the order of a few thousand Qlik Sense servers exposed to the internet
CVE-2024-12356
Unauthenticated Command Injection in BeyondTrust Privileged Remote Access/Remote Support

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an unauthenticated command injection flaw (CWE-77) that allows a remote attacker to inject commands that are executed as a site user. The vulnerability is network-facing with low attack complexity and requires no privileges or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so any attacker who can reach the affected PRA/RS interface can trigger it. Successful exploitation yields arbitrary command execution in the context of the site user, with high impact ratings for confidentiality, integrity, and availability. Any organization running BeyondTrust PRA or RS — particularly where those remote-access/remote-support services are exposed to the internet — is affected; the available data does not specify affected version ranges. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-19, carries an 88% EPSS probability of exploitation within 30 days (100th percentile), and was reportedly used in the breach of the U.S. Treasury alongside a PostgreSQL vulnerability.

Do: Apply BeyondTrust's patches or vendor-specified mitigations immediately — remediation is mandatory for U.S. federal agencies under the KEV listing, and the source data does not include fixed build numbers, so confirm the correct upgrade version in BeyondTrust's security bulletin. As an interim measure, restrict or remove internet exposure of PRA/RS endpoints and hunt for signs of exploitation (unexpected commands executed as the site user), noting this flaw was used in the U.S. Treasury intrusion. If mitigations are unavailable, CISA's required action is to discontinue use of the product.

9.888% KEV PoC
  • BeyondTrust Privileged Remote Access (PRA)
  • BeyondTrust Remote Support (RS)
moderate≈ a few thousand internet-exposed PRA/RS instances (order-of-magnitude estimate from public internet scans)
CVE-2024-12686
OS Command Injection in BeyondTrust Privileged Remote Access and Remote Support

CVE-2024-12686 is an OS command injection flaw (CWE-78) in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) that is reachable over the network but requires the attacker to already hold administrative privileges in the product. By injecting commands through an administrative function, the attacker gets arbitrary commands executed on the underlying host as the site user, producing high impact to confidentiality, integrity, and availability in that context. Organizations running BeyondTrust PRA or RS — commonly deployed for privileged remote support and help-desk access — are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-01-13, confirming exploitation in the wild, and EPSS assigns a 13.8% probability of exploitation within 30 days (96th percentile). The flaw arrives amid a broader wave of BeyondTrust attacks, including the related zero-day CVE-2024-12356 tied to a compromised API key that exposed 17 SaaS customers and was used by a China-linked actor against U.S. Treasury systems, and reported chaining with a PostgreSQL flaw in targeted attacks.

Do: Upgrade all PRA and RS deployments to the fixed releases identified in BeyondTrust's security bulletin for CVE-2024-12686 (including any SaaS instances managed by BeyondTrust), and apply the mitigations required by the CISA KEV entry if patching must be deferred. Because exploitation requires administrative access, review and rotate privileged and API credentials — especially given the related API-key compromise behind CVE-2024-12356 — restrict administrative console exposure to trusted networks, and check logs for unexpected commands executed as the site user.

7.214% KEV
  • BeyondTrust Privileged Remote Access (PRA)
  • BeyondTrust Remote Support (RS)
moderatelikely on the order of thousands of exposed PRA/RS instances (estimate; no install counts in source data)
Full article440 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 14, 2025Vulnerability / Cybersecurity

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a second security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

The vulnerability in question is CVE-2024-12686 (CVSS score: 6.6), a medium-severity bug that could allow an attacker with existing administrative privileges to inject commands and run as a site user.

"BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file," CISA said.

"Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user."

The addition of CVE-2024-12686 to the KEV catalog comes nearly a month after it added another critical security flaw impacting the same product (CVE-2024-12356, CVSS score: 9.8) that could also lead to the execution of arbitrary commands.

BeyondTrust said both vulnerabilities were discovered as part of its investigation into a cyber incident in early December 2024 that involved malicious actors leveraging a compromised Remote Support SaaS API key to breach some of the instances, and reset passwords for local application accounts.

Although the API key has since been revoked, the exact manner in which the key was compromised remains unknown as yet. It's suspected that the threat actors exploited the two flaws as zero-days to break into BeyondTrust systems.

Earlier this month, the U.S. Treasury Department revealed its network was breached using the compromised API key in what it said was a "major cybersecurity incident." The hack has been pinned on a Chinese state-sponsored group called Silk Typhoon (aka Hafnium).

The threat actors are believed to have specifically targeted the Treasury's Office of Foreign Assets Control (OFAC), Office of Financial Research, and the Committee on Foreign Investment in the United States (CFIUS), according to multiple reports from the Washington Post and CNN.

Also added to the KEV catalog is a now-patched critical security vulnerability affecting Qlik Sense (CVE-2023-48365, CVSS score: 9.9) that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.

It's worth noting that the security flaw has been actively exploited in the past by the Cactus ransomware group. Federal agencies are required to apply the necessary patches by February 3, 2024, to secure their networks against active threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/01/cisa-adds-new-beyondtrust-flaw-to-kev.html