CVE-2024-12686: BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2025-01-13. EPSS: 13.7% chance of exploitation in the next 30 days.
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
Affected products
- BeyondTrust Privileged Remote Access: up to and including 24.3.1
- BeyondTrust Remote Support: up to and including 24.3.1
Published 2024-12-18. Last modified 2026-06-17.