CVE-2024-12356: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-12-19. EPSS: 87.3% chance of exploitation in the next 30 days.
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Affected products
- BeyondTrust Privileged Remote Access: up to and including 24.3.1
- BeyondTrust Remote Support: up to and including 24.3.1
Published 2024-12-17. Last modified 2026-06-17.