HIGH

CVE-2024-12686

Beyondtrust Privileged Remote Access 2024-12-18 CVSS v3.1
CVSS
7.2
KEV

Description

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.

Summary dbcve.org

This is a command injection vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products. An authenticated administrator can inject arbitrary commands that execute in the context of a site user, enabling privilege escalation beyond their assigned administrative role.

Mitigation

Apply the vendor patch when available and audit administrative user accounts to ensure only trusted personnel have access. Follow the principle of least privilege for administrative roles.

Weakness (CWE)

CWE-78 OS Command Injection

EPSS Score

13.79%
Probability of exploitation in next 30 days
96.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE