Vulnerability record · CVE-2024-12686 · published 18 December 2024
CVE-2024-12686: BeyondTrust PRA and RS OS command injection by admin
Beyondtrust · Privileged Remote Access
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection flaw (CWE-78). An attacker who already holds administrative privileges can inject commands and execute them as a site user, crossing a privilege boundary within the product. It matters because it lets a high-privileged insider or a compromised admin account escalate into site-user context on a remote access platform.
Description
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with known exploitation and high EPSS, but requires existing administrative privileges, which limits the attacker population.
What it is
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection flaw (CWE-78). An attacker who already holds administrative privileges can inject commands and execute them as a site user, crossing a privilege boundary within the product. It matters because it lets a high-privileged insider or a compromised admin account escalate into site-user context on a remote access platform.
Impact
An attacker with existing administrative privileges gains the ability to run arbitrary commands as a site user, potentially accessing data or functionality scoped to that user. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network (AV:N) with low attack complexity, but it requires high privileges (PR:H) and no user interaction (UI:N). The description does not specify the exact interface or parameter used for injection.
Exploitation
CVE-2024-12686 is listed in CISA KEV with a due date of 2025-02-03, indicating known exploitation, though CISA records no known ransomware campaign use. EPSS gives a 30-day probability of about 13.8 percent (96th percentile).
What to do
- Apply the vendor fix per the BeyondTrust advisory BT24-11; patch is the first action.
- If patching is not immediately possible, follow CISA's required action: apply vendor mitigations or discontinue use of the product.
- Restrict and audit administrative accounts on PRA and RS; remove unnecessary admin rights and enforce least privilege.
- Monitor and limit network exposure of PRA and RS management interfaces.
- Review logs for unexpected command execution or site-user activity originating from admin sessions.
Detection
- Hunt for command execution or process creation on PRA/RS hosts spawned by the application service account.
- Alert on administrative sessions that produce activity in a site-user context or unexpected child processes.
- Correlate admin logins with subsequent command-line or shell activity on the same host.
- Review BeyondTrust audit logs for anomalous command injection patterns around the advisory timeframe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-12686 to the Known Exploited Vulnerabilities catalog on 13 January 2025 as "BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 February 2025.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://nvd.nist.gov/vuln/detail/CVE-2024-12686 | Third Party AdvisoryUS Government Resource |
| https://www.beyondtrust.com/trust-center/security-advisories/bt24-11 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-12686 | US Government Resource |
Track CVE-2024-12686 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-12686), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.