← Vulnerability feed

Vulnerability record · CVE-2024-12686 · published 18 December 2024

CVE-2024-12686: BeyondTrust PRA and RS OS command injection by admin

Beyondtrust · Privileged Remote Access

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection flaw (CWE-78). An attacker who already holds administrative privileges can inject commands and execute them as a site user, crossing a privilege boundary within the product. It matters because it lets a high-privileged insider or a compromised admin account escalate into site-user context on a remote access platform.

7.2 CVSS 3.1 High CISA KEV since 13 Jan 2025 EPSS 14% · top 3.6% CWE-78 · OS command injection
7.2CVSS 3.1 base score
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is in CISA KEV with known exploitation and high EPSS, but requires existing administrative privileges, which limits the attacker population.

What it is

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection flaw (CWE-78). An attacker who already holds administrative privileges can inject commands and execute them as a site user, crossing a privilege boundary within the product. It matters because it lets a high-privileged insider or a compromised admin account escalate into site-user context on a remote access platform.

Impact

An attacker with existing administrative privileges gains the ability to run arbitrary commands as a site user, potentially accessing data or functionality scoped to that user. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reachable over the network (AV:N) with low attack complexity, but it requires high privileges (PR:H) and no user interaction (UI:N). The description does not specify the exact interface or parameter used for injection.

Exploitation

CVE-2024-12686 is listed in CISA KEV with a due date of 2025-02-03, indicating known exploitation, though CISA records no known ransomware campaign use. EPSS gives a 30-day probability of about 13.8 percent (96th percentile).

What to do

  • Apply the vendor fix per the BeyondTrust advisory BT24-11; patch is the first action.
  • If patching is not immediately possible, follow CISA's required action: apply vendor mitigations or discontinue use of the product.
  • Restrict and audit administrative accounts on PRA and RS; remove unnecessary admin rights and enforce least privilege.
  • Monitor and limit network exposure of PRA and RS management interfaces.
  • Review logs for unexpected command execution or site-user activity originating from admin sessions.

Detection

  • Hunt for command execution or process creation on PRA/RS hosts spawned by the application service account.
  • Alert on administrative sessions that produce activity in a site-user context or unexpected child processes.
  • Correlate admin logins with subsequent command-line or shell activity on the same host.
  • Review BeyondTrust audit logs for anomalous command injection patterns around the advisory timeframe.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-12686 to the Known Exploited Vulnerabilities catalog on 13 January 2025 as "BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 February 2025.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-12686 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-1731BeyondTrust Remote Support and PRA pre-auth OS command injectionBeyondTrust Remote Support and certain older Privileged Remote Access versions contain an OS command injection flaw (CWE-78) reachable before authent…KEVEPSS 91%analysed9.8CVE-2024-12356BeyondTrust PRA and RS unauthenticated command injectionBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection flaw (CWE-77) that lets an unauthenticated attacker in…KEVEPSS 87%analysed9.8CVE-2023-4310Beyondtrust privileged remote access command injection vulnerabilityBeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 contain a command injection vulnerability which can be …EPSS 1.8%9.2CVE-2026-40138Beyondtrust privileged remote access improper authentication vulnerabilityA critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improp…EPSS 0.46%9.2CVE-2026-40139Beyondtrust privileged remote access improper authentication vulnerabilityA critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authenticati…EPSS 0.75%8.7CVE-2026-40140Beyondtrust privileged remote access uncontrolled resource consumption vulnerabilityBeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsyst…EPSS 0.65%8.6CVE-2025-5309Beyondtrust privileged remote access code injection vulnerabilityThe chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which …EPSS 0.95%8.5CVE-2026-40141Beyondtrust privileged remote access vulnerabilityA high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the process…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2024-12686), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.