Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Feb 3, 2025

CVE-2024-12686

High
EPSS 33.4%CISA KEV
BeyondTrust/Privileged Remote Access (PRA) and Remote Support (RS)

Description

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.

EPSS — Exploit Probability

33.4%

Higher than 96.9% of all CVEs

Required Action

https://www.beyondtrust.com/trust-center/security-advisories/bt24-11 ; https://nvd.nist.gov/vuln/detail/CVE-2024-12686

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
33.4%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Jan 13, 2025

Added to KEV

Jan 13, 2025

Remediation Due

Feb 3, 2025

Affected Product

BeyondTrust

Privileged Remote Access (PRA) and Remote Support (RS)

View all BeyondTrust CVEs