{"cvss":6.6,"datePublished":"2025-01-13","dateUpdated":"2025-01-13","description":"BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.","dueDate":"2025-02-03","id":"CVE-2024-12686","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Unknown","notes":"https://www.beyondtrust.com/trust-center/security-advisories/bt24-11 ; https://nvd.nist.gov/vuln/detail/CVE-2024-12686","product":"Privileged Remote Access (PRA) and Remote Support (RS)","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","severity":"MEDIUM","source":"cisa_known_exploited","title":"BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability","vendor":"BeyondTrust"}