LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-12356: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 19, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 27, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-12356 to its Known Exploited Vulnerabilities catalog on Dec 19, 2024, with a federal patch deadline of Dec 27, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site…

CVE-2024-12356 is a command injection vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS). An unauthenticated attacker can inject commands that execute as a site user. Because these products manage privileged remote access, successful abuse can give an outsider a foothold on systems that control sensitive administrative sessions. Confirm all product-specific details against the vendor advisory.

CISA notes that organizations should apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Ransomware use of this CVE is not documented.

How it works

The flaw is classified as CWE-77 (command injection). In products of this class, user-supplied input reaches a shell or command interpreter without sufficient sanitization. An attacker who can reach the vulnerable interface can craft input that the application treats as part of an operating-system command. Because the CVE summary states the injected commands run as a site user and no authentication is required, the attacker does not need prior credentials. Exact injection points, request formats, and payload construction are not provided in the public summary; treat any technical reproduction details as unconfirmed until verified against the vendor advisory.

Am I affected? How to find it in your systems

BeyondTrust PRA and RS are typically deployed as appliances or virtual appliances that broker privileged remote sessions for IT and support staff. They often sit at the network edge or in a DMZ so that external technicians can reach internal systems under controlled conditions.

How to remediate

Patch first. Apply the vendor-supplied update that addresses CVE-2024-12356 as soon as it is available and tested in your environment. Confirm the exact package name, version, and installation procedure against the official BeyondTrust advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls.

If your data may have been exposed

Actively exploited command-injection flaws can lead to unauthorized access and subsequent data exposure. If you have evidence that an unauthenticated attacker reached a vulnerable PRA or RS instance, treat the environment as potentially compromised: rotate credentials used by the product, review session logs for unauthorized privileged activity, and follow your incident-response plan. You can also run a free exposure scan of your email addresses to check whether those addresses appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedBeyondTrust · Privileged Remote Access (PRA) and Remote Support (RS)
WeaknessCWE-77
Added to CISA KEVDec 19, 2024
Federal patch deadlineDec 27, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities