CVE-2024-12686: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
Other sources
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12686?
CVE-2024-12686 has been rated with a high severity level due to its potential for privilege escalation.
How do I fix CVE-2024-12686?
To fix CVE-2024-12686, users should update to the latest version of BeyondTrust Privileged Remote Access and Remote Support beyond version 24.3.1.
Who is affected by CVE-2024-12686?
CVE-2024-12686 affects users of BeyondTrust Privileged Remote Access and Remote Support versions up to and including 24.3.1.
What can an attacker do with CVE-2024-12686?
An attacker with existing administrative privileges can exploit CVE-2024-12686 to inject commands and run processes as a site user.
What products are involved in CVE-2024-12686?
CVE-2024-12686 specifically involves BeyondTrust's Privileged Remote Access (PRA) and Remote Support (RS) products.