CVE-2024-12356
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
- Affected products
- Beyondtrust Privileged Remote Access, Beyondtrust Remote Support
- Beyondtrust Privileged Remote Access
- β€ 24.3.1
- Beyondtrust Remote Support
- β€ 24.3.1
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 88.0% (100th percentile)
- Weakness
- CWE-77
- NVD status
- Analyzed
- Published
- 2024-12-17
- Attack patterns
- CAPEC-88
- Entry point
- gskey path
- Path
- /nw
CVE-2024-12356 at NVD
8 known exploits for CVE-2024-12356
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2024-12356
π BeyondTrust PRA / RS Unauthenticated Remote Code Execution
Exploit for CVE-2026-1731
Exploit for CVE-2026-1731
Exploit for CVE-2025-1094
BeyondTrust Remote Code Execution Exploit
BeyondTrust Remote Code Execution
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution