CVE-2025-5309: BeyondTrust Privileged Remote Access
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
Affected products
- BeyondTrust Privileged Remote Access: from 24.2.2, up to and including 24.2.4; from 24.3.1, before 24.3.4 (fixed in 24.3.4); version 25.1.1 only
- BeyondTrust Remote Support: from 24.2.2, up to and including 24.2.4; from 24.3.1, before 24.3.4 (fixed in 24.3.4); version 25.1.1 only
Published 2025-06-16. Last modified 2026-06-17.