HIGH
CVE-2024-12686
CVSS
7.2
KEV
Description
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
Summary dbcve.org
This is a command injection vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products. An authenticated administrator can inject arbitrary commands that execute in the context of a site user, enabling privilege escalation beyond their assigned administrative role.
Mitigation
Apply the vendor patch when available and audit administrative user accounts to ensure only trusted personnel have access. Follow the principle of least privilege for administrative roles.
Weakness (CWE)
CWE-78
OS Command Injection
EPSS Score
13.79%
Probability of exploitation in next 30 days
96.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.