CVE-2024-12686

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Dec 18, 2024
Updated: Jan 14, 2025
CWE ID 78

Summary

CVE-2024-12686 is a recently disclosed vulnerability affecting Privileged Remote Access (PRA) and Remote Support (RS) systems. This issue grants attackers with administrative privileges the ability to inject commands and operate as a site user, expanding their access and potential impact within an organization. While the exact details of the exploit are not yet publicly available, it is important for administrators to prioritize patches and mitigations to prevent potential exploitation. This vulnerability highlights the importance of securing remote access solutions to protect against insider threats and unauthorized access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • BeyondTrust
  • BeyondTrust Privileged Remote Access
  • BeyondTrust Remote Support

Affected Vendors

  • BeyondTrust Software Corp