Start with Identity
Identity CVE · Other

CVE-2024-12356BeyondTrust PRA and Remote Support unauthenticated command injection

critical · CVSS 9.8CISA KEVActively exploited
Product: BeyondTrust Privileged Remote Access / Remote SupportVendor: BeyondTrustDisclosed: 2024-12-16Status: Actively exploitedNVD ↗CISA KEV ↗

What broke

BeyondTrust Privileged Remote Access and Remote Support (BT24-10) executed operating-system commands from a malicious client request, with no login. CVSS 9.8. Disclosed 16 December 2024. CISA added it to KEV. Patched in RS/PRA 22.1.x and later trains. Hundreds of on-prem appliances were still on the internet weeks later.

Why it matters

PRA is how vendors and admins become a privileged user on someone else's box. Unauthenticated command injection there is a PAM incident: recorded sessions, vaulted credentials, and jump-host identity all sit behind that login. Same product class as ScreenConnect and Conjur.

What to do

  • Patch PRA/RS. Confirm the build, including vendor-hosted and customer-hosted.
  • If the appliance was reachable in December 2024, rotate every vaulted credential it could check out and review session recordings for gaps.
  • Take PRA admin off the internet. The jump path is the product. The management plane is not.

After you patch

Remote management and support platforms are standing administrative access to every endpoint beneath them, which turns a single bypass into a many-customer incident.

  • Revoke sessions and rotate the platform's own credentials, including agent enrolment keys.
  • Review remote session logs for connections you cannot attribute to a technician.
  • Look for independent egress the attacker may have added, such as new tunnel services or remote access tools on managed endpoints, because removing them from the console does not remove them from the network.
  • Treat the platform as tier-zero privileged access in your access model going forward, not as IT tooling.

Sources

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Know a primary source we should add, or a patch status that has changed? Email community@startwithidentity.com. See all briefs in the identity CVE catalog, or volunteer as a CVE Analyst.
Compiled from vendor advisories, NVD, CISA KEV, and public research. CVSS figures can disagree across NVD and the CNA. Confirm affected versions against the vendor advisory before you patch. Independent, community-driven analysis. See the disclaimer.