• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
beyondtrust issues urgent patch for critical vulnerability in pra and

BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products

You are here: Home / General Cyber Security News / BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products
December 18, 2024

BeyondTrust has disclosed details of a critical security flaw in Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to the execution of arbitrary commands.

Privileged Remote Access controls, manages, and audits privileged accounts and credentials, offering zero trust access to on-premises and cloud resources by internal, external, and third-party users. Remote Support allows service desk personnel to securely connect to remote systems and mobile devices.

The vulnerability, tracked as CVE-2024-12356 (CVSS score: 9.8), has been described as an instance of command injection.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Cybersecurity

“A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user,” the company said in an advisory.

An attacker could exploit the flaw by sending a malicious client request, effectively leading to the execution of arbitrary operating systems within the context of the site user.

The issue impacts the following versions –

  • Privileged Remote Access (versions 24.3.1 and earlier) – Fixed in PRA patch BT24-10-ONPREM1 or BT24-10-ONPREM2
  • Remote Support (versions 24.3.1 and earlier) – Fixed in RS patch BT24-10-ONPREM1 or BT24-10-ONPREM2

A patch for the vulnerability has already been applied to cloud instances as of December 16, 2024. Users of on-premise versions of the software are recommended to apply the latest fixes if they are not subscribed to automatic updates.

“If customers are on a version older than 22.1, they will need to upgrade in order to apply this patch,” BeyondTrust said.

Cybersecurity

The company said the shortcoming was uncovered during an ongoing forensics investigation that was initiated following a “security incident” on December 2, 2024, involving a “limited number of Remote Support SaaS customers.”

“A root cause analysis into a Remote Support SaaS issue identified an API key for Remote Support SaaS had been compromised,” BeyondTrust said, adding it “immediately revoked the API key, notified known impacted customers, and suspended those instances the same day while providing alternative Remote Support SaaS instances for those customers.”

BeyondTrust also said it’s still working to determine the cause and impact of the compromise in partnership with an unnamed “cybersecurity and forensics firm.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «interpol pushes for "romance baiting" to replace "pig butchering" in INTERPOL Pushes for “Romance Baiting” to Replace “Pig Butchering” in Scam Discourse
Next Post: ONLY Cynet Delivers 100% Protection and 100% Detection Visibility in the 2024 MITRE ATT&CK Evaluation only cynet delivers 100% protection and 100% detection visibility in»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • BREAKING: 7,000-Device Proxy Botnet Using IoT, EoL Systems Dismantled in U.S. – Dutch Operation
  • OtterCookie v4 Adds VM Detection and Chrome, MetaMask Credential Theft Capabilities
  • Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials
  • Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business
  • Malicious npm Packages Infect 3,200+ Cursor Users With Backdoor, Steal Credentials
  • Beyond Vulnerability Management – Can You CVE What I CVE?
  • Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android
  • Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
  • 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases
  • SonicWall Patches 3 Flaws in SMA 100 Devices Allowing Attackers to Run Code as Root

Copyright © TheCyberSecurity.News, All Rights Reserved.