Identity CVE · Other
CVE-2024-12356BeyondTrust PRA and Remote Support unauthenticated command injection
critical · CVSS 9.8CISA KEVActively exploited
Product: BeyondTrust Privileged Remote Access / Remote SupportVendor: BeyondTrustDisclosed: 2024-12-16Status: Actively exploitedNVD ↗CISA KEV ↗
What broke
BeyondTrust Privileged Remote Access and Remote Support (BT24-10) executed operating-system commands from a malicious client request, with no login. CVSS 9.8. Disclosed 16 December 2024. CISA added it to KEV. Patched in RS/PRA 22.1.x and later trains. Hundreds of on-prem appliances were still on the internet weeks later.
Why it matters
PRA is how vendors and admins become a privileged user on someone else's box. Unauthenticated command injection there is a PAM incident: recorded sessions, vaulted credentials, and jump-host identity all sit behind that login. Same product class as ScreenConnect and Conjur.
What to do
- Patch PRA/RS. Confirm the build, including vendor-hosted and customer-hosted.
- If the appliance was reachable in December 2024, rotate every vaulted credential it could check out and review session recordings for gaps.
- Take PRA admin off the internet. The jump path is the product. The management plane is not.
Sources
- NVD: CVE-2024-12356
- BeyondTrust BT24-10
- CISA KEV
Related identity CVEs
Know a primary source we should add, or a patch status that has changed? Email [email protected]. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.