Start with Identity
Identity CVE · Other

CVE-2024-12356BeyondTrust PRA and Remote Support unauthenticated command injection

critical · CVSS 9.8CISA KEVActively exploited
Product: BeyondTrust Privileged Remote Access / Remote SupportVendor: BeyondTrustDisclosed: 2024-12-16Status: Actively exploitedNVD ↗CISA KEV ↗

What broke

BeyondTrust Privileged Remote Access and Remote Support (BT24-10) executed operating-system commands from a malicious client request, with no login. CVSS 9.8. Disclosed 16 December 2024. CISA added it to KEV. Patched in RS/PRA 22.1.x and later trains. Hundreds of on-prem appliances were still on the internet weeks later.

Why it matters

PRA is how vendors and admins become a privileged user on someone else's box. Unauthenticated command injection there is a PAM incident: recorded sessions, vaulted credentials, and jump-host identity all sit behind that login. Same product class as ScreenConnect and Conjur.

What to do

  • Patch PRA/RS. Confirm the build, including vendor-hosted and customer-hosted.
  • If the appliance was reachable in December 2024, rotate every vaulted credential it could check out and review session recordings for gaps.
  • Take PRA admin off the internet. The jump path is the product. The management plane is not.

Sources

Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.