CVE-2025-5309: Remote Support & Privileged Remote Access server side template injection
Published Jun 16, 2025
·Updated
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
Affected Software
8 affected components
Remote Support Remote Support
Privileged Remote Access Privileged Remote Access
BeyondTrust Privileged Remote Access>=24.2.2<=24.2.4
BeyondTrust Privileged Remote Access>=24.3.1<24.3.4
BeyondTrust Privileged Remote Access=25.1.1
BeyondTrust Remote Support>=24.2.2<=24.2.4
BeyondTrust Remote Support>=24.3.1<24.3.4
BeyondTrust Remote Support=25.1.1
Event History
Jun 16, 2025
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Jun 18, 2025
News Published
via BleepingComputer·10:10 AM
News Published
via BleepingComputer·10:11 AM
May 12, 57609
Event
via NVD·01:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-5309?
CVE-2025-5309 is classified as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-5309?
To fix CVE-2025-5309, apply the latest security patches provided by Remote Support and Privileged Remote Access vendors.
3
What types of attacks can exploit CVE-2025-5309?
CVE-2025-5309 can be exploited through server-side template injection, potentially leading to unauthorized remote code execution.
4
Which software is affected by CVE-2025-5309?
CVE-2025-5309 affects the Remote Support and Privileged Remote Access software products.
5
Is CVE-2025-5309 a pre-authentication vulnerability?
Yes, CVE-2025-5309 is a pre-authentication vulnerability, allowing attackers to exploit it without prior authentication.