← Vulnerability feed

Vulnerability record · CVE-2024-12356 · published 17 December 2024

CVE-2024-12356: BeyondTrust PRA and RS unauthenticated command injection

Beyondtrust · Privileged Remote Access

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection flaw (CWE-77) that lets an unauthenticated attacker inject commands executed as a site user. With a CVSS 3.1 score of 9.8 and network reachability with no privileges or user interaction, this is a severe pre-auth remote code execution risk for exposed deployments.

9.8 CVSS 3.1 Critical CISA KEV since 19 Dec 2024 EPSS 87% · top 0.3% CWE-77 · Command injection
9.8CVSS 3.1 base score
87%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityPre-auth network command injection with a 9.8 CVSS score, active KEV listing, and near-maximum EPSS probability make this an urgent patch-or-isolate case.

What it is

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection flaw (CWE-77) that lets an unauthenticated attacker inject commands executed as a site user. With a CVSS 3.1 score of 9.8 and network reachability with no privileges or user interaction, this is a severe pre-auth remote code execution risk for exposed deployments.

Impact

An attacker gains arbitrary command execution in the context of a site user on the affected appliance, which can lead to full compromise of the remote access platform and any credentials or sessions it brokers.

Attack surface

Reachable over the network (AV:N) with no authentication (PR:N) and no user interaction (UI:N) required, per the CVSS vector. The description does not specify the exact endpoint or protocol, so defenders should treat any internet-exposed PRA/RS interface as in scope.

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2024-12-19 with a 2024-12-27 remediation due date, and EPSS shows a 30-day probability of 0.87991 (99.756th percentile). A reference is tagged Exploit, indicating public exploit analysis exists; no ransomware campaign use is documented.

What to do

  • Apply the vendor patch or mitigations from BeyondTrust advisory BT24-10 immediately.
  • If patching is not possible, remove internet exposure of PRA and RS interfaces or discontinue use per CISA guidance.
  • Restrict management and remote access interfaces to trusted networks or VPN, and block unnecessary inbound access.
  • Rotate credentials and secrets that were accessible to the affected appliance, since commands run as a site user.
  • Review logs and configurations for signs of prior compromise before restoring normal exposure.

Detection

  • Hunt for unexpected child processes or shell invocations spawned by the PRA/RS web service on the appliance.
  • Monitor appliance and web logs for anomalous requests to PRA/RS endpoints, especially from unfamiliar source IPs.
  • Alert on new or modified files, scheduled tasks, or outbound connections originating from the PRA/RS host.
  • Correlate authentication and session records for site users with command execution events around the same timeframe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-12356 to the Known Exploited Vulnerabilities catalog on 19 December 2024 as "BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 27 December 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-12356 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-1731BeyondTrust Remote Support and PRA pre-auth OS command injectionBeyondTrust Remote Support and certain older Privileged Remote Access versions contain an OS command injection flaw (CWE-78) reachable before authent…KEVEPSS 91%analysed7.2CVE-2024-12686BeyondTrust PRA and RS OS command injection by adminBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection flaw (CWE-78). An attacker who already holds admin…KEVEPSS 14%analysed9.8CVE-2023-4310Beyondtrust privileged remote access command injection vulnerabilityBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be …EPSS 1.8%9.2CVE-2026-40138Beyondtrust privileged remote access improper authentication vulnerabilityA critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improp…EPSS 0.46%9.2CVE-2026-40139Beyondtrust privileged remote access improper authentication vulnerabilityA critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authenticati…EPSS 0.75%8.7CVE-2026-40140Beyondtrust privileged remote access uncontrolled resource consumption vulnerabilityBeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsyst…EPSS 0.65%8.6CVE-2025-5309Beyondtrust privileged remote access code injection vulnerabilityThe chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which …EPSS 0.95%8.5CVE-2026-40141Beyondtrust privileged remote access vulnerabilityA high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the process…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2024-12356), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.