LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-12686: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 13, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 3, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-12686 to its Known Exploited Vulnerabilities catalog on Jan 13, 2025, with a federal patch deadline of Feb 3, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload…

CVE-2024-12686 is an OS command injection vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS). An attacker who already holds administrative privileges can abuse it by uploading a malicious file, which then allows execution of underlying operating system commands in the context of the site user. Because these products sit at the center of privileged remote access and support workflows, successful exploitation can give an attacker a foothold to run commands on the host, potentially expanding control over sensitive systems and sessions that the software manages.

Defenders should treat this as a high-priority issue for any environment running PRA or RS. Public detail is limited to the CISA summary and the CWE-78 classification; exact affected versions, patch identifiers, and full technical mechanics must be confirmed against the vendor advisory.

How it works

The flaw is classified as CWE-78, OS command injection. In products of this class, user-controlled or attacker-supplied input is insufficiently sanitized before being passed to a system shell or command interpreter. According to the available summary, an attacker who already possesses administrative privileges can upload a malicious file. That file is then processed in a way that injects and executes operating-system commands under the privileges of the site user.

No further exploit mechanics, payload formats, or attack chains are provided in the public record. Exploitation therefore requires prior administrative access; it is not described as a fully unauthenticated remote code execution path. Once the injected commands run, the attacker can perform whatever actions the site-user context permits on the underlying host. Confirm the precise injection point and required conditions against the vendor advisory before modeling the attack surface.

Am I affected? How to find it in your systems

BeyondTrust PRA and RS are typically deployed as appliances, virtual machines, or software instances that provide privileged remote access, jump-server functionality, and remote support sessions for IT and help-desk teams. They often sit in management or DMZ networks and hold credentials or session data for high-value systems.

If the software is present and the version matches an affected release listed by the vendor, treat the system as vulnerable until patched or mitigated.

How to remediate

The primary remediation is to apply the vendor-supplied update or mitigation instructions for CVE-2024-12686. CISA’s required action is to apply mitigations per vendor instructions or to discontinue use of the product if mitigations are unavailable. Obtain the official advisory from BeyondTrust, identify the fixed package or configuration change for your exact PRA or RS release, and deploy it through your normal change-control process.

Document the remediation in your vulnerability-management system and re-scan to confirm closure.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that address the prerequisites and impact of this OS command-injection class.

These measures lower the likelihood that an already-privileged attacker can successfully inject commands, but they do not replace the vendor patch.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to full host compromise and subsequent data exposure or lateral movement. Known ransomware use is not documented for CVE-2024-12686. If you have reason to believe the vulnerability was leveraged in your environment, follow your incident-response plan: isolate affected hosts, preserve forensic evidence, and assess whether credentials, session data, or other sensitive material handled by PRA/RS were accessed. As a general hygiene step, you can run a free exposure scan of your email addresses against known breach data sets to check whether any associated accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedBeyondTrust · Privileged Remote Access (PRA) and Remote Support (RS)
WeaknessCWE-78
Added to CISA KEVJan 13, 2025
Federal patch deadlineFeb 3, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities