# BeyondTrust PRA and Remote Support unauthenticated command injection

Source: https://startwithidentity.com/cves/cve-2024-12356/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

[BeyondTrust](https://startwithidentity.com/vendors/pam/beyondtrust/) Privileged Remote Access and Remote Support (BT24-10) executed operating-system commands from a malicious client request, with no login. CVSS 9.8. Disclosed 16 December 2024. CISA added it to KEV. Patched in RS/PRA 22.1.x and later trains. Hundreds of on-prem appliances were still on the internet weeks later.

## Why it matters

PRA is how vendors and admins become a privileged user on someone else's box. Unauthenticated command injection there is a [PAM](https://startwithidentity.com/glossary/pam/) incident: recorded sessions, vaulted credentials, and jump-host identity all sit behind that login. Same product class as [ScreenConnect](https://startwithidentity.com/cves/cve-2024-1709/) and [Conjur](https://startwithidentity.com/cves/cve-2025-49827/).

## What to do

- Patch PRA/RS. Confirm the build, including vendor-hosted and customer-hosted.
- If the appliance was reachable in December 2024, rotate every vaulted credential it could check out and review session recordings for gaps.
- Take PRA admin off the internet. The jump path is the product. The management plane is not.

## After you patch

Remote management and support platforms are standing administrative access to every endpoint beneath them, which turns a single bypass into a many-customer incident.

- **Revoke sessions and rotate the platform's own credentials**, including agent enrolment keys.
- **Review remote session logs** for connections you cannot attribute to a technician.
- **Look for independent egress the attacker may have added**, such as new tunnel services or remote access tools on managed endpoints, because removing them from the console does not remove them from the network.
- **Treat the platform as tier-zero [privileged access](https://startwithidentity.com/guides/fundamentals/what-is-pam/)** in your access model going forward, not as IT tooling.

## Sources

- [NVD: CVE-2024-12356](https://nvd.nist.gov/vuln/detail/CVE-2024-12356)
- BeyondTrust BT24-10
- CISA KEV
