Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products

The Hacker News by The Hacker News
December 26, 2024
Home Cybersecurity
Share on FacebookShare on Twitter


Dec 18, 2024Ravie LakshmananSaaS Security / Incident Response

BeyondTrust has disclosed details of a critical security flaw in Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to the execution of arbitrary commands.

Privileged Remote Access controls, manages, and audits privileged accounts and credentials, offering zero trust access to on-premises and cloud resources by internal, external, and third-party users. Remote Support allows service desk personnel to securely connect to remote systems and mobile devices.

The vulnerability, tracked as CVE-2024-12356 (CVSS score: 9.8), has been described as an instance of command injection.

Cybersecurity

“A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user,” the company said in an advisory.

An attacker could exploit the flaw by sending a malicious client request, effectively leading to the execution of arbitrary operating systems within the context of the site user.

The issue impacts the following versions –

  • Privileged Remote Access (versions 24.3.1 and earlier) – Fixed in PRA patch BT24-10-ONPREM1 or BT24-10-ONPREM2
  • Remote Support (versions 24.3.1 and earlier) – Fixed in RS patch BT24-10-ONPREM1 or BT24-10-ONPREM2

A patch for the vulnerability has already been applied to cloud instances as of December 16, 2024. Users of on-premise versions of the software are recommended to apply the latest fixes if they are not subscribed to automatic updates.

“If customers are on a version older than 22.1, they will need to upgrade in order to apply this patch,” BeyondTrust said.

Cybersecurity

The company said the shortcoming was uncovered during an ongoing forensics investigation that was initiated following a “security incident” on December 2, 2024, involving a “limited number of Remote Support SaaS customers.”

“A root cause analysis into a Remote Support SaaS issue identified an API key for Remote Support SaaS had been compromised,” BeyondTrust said, adding it “immediately revoked the API key, notified known impacted customers, and suspended those instances the same day while providing alternative Remote Support SaaS instances for those customers.”

BeyondTrust also said it’s still working to determine the cause and impact of the compromise in partnership with an unnamed “cybersecurity and forensics firm.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
The Hacker News

The Hacker News

Next Post
The Edgelord AI That Turned a Shock Meme Into Millions in Crypto

The Edgelord AI That Turned a Shock Meme Into Millions in Crypto

Recommended.

HOTWORX Launches TrainingTRAX, Amplifying Fitness with AI-Powered Coaching

HOTWORX Launches TrainingTRAX, Amplifying Fitness with AI-Powered Coaching

April 22, 2026
„Global Connectivity • Industry Interaction” Internationaler Sportindustrie-Salon in Hongkong abgehalten

„Global Connectivity • Industry Interaction” Internationaler Sportindustrie-Salon in Hongkong abgehalten

June 20, 2025

Trending.

CELLCOM ISRAEL LTD. Announcement of A Special General Meeting of The Shareholders of The Company

CELLCOM ISRAEL LTD. Announcement of A Special General Meeting of The Shareholders of The Company

May 21, 2025
AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

AWS Vs. Google Cloud Vs. Microsoft Azure Q1 Earnings Face-Off

May 1, 2026
Veeam Debuts Data Resiliency Maturity Model To Assess, Improve Customers’ Cyber Resiliency

Veeam Debuts Data Resiliency Maturity Model To Assess, Improve Customers’ Cyber Resiliency

April 23, 2025
MocPOGO Easter Special Deals: The Pokémon GO Spoofer You Need for Might and Mastery 2025!

MocPOGO Easter Special Deals: The Pokémon GO Spoofer You Need for Might and Mastery 2025!

April 7, 2025
VNET Wins 40MW Wholesale Order from Leading Internet Company for Its New Strategic IDC Campus

VNET Wins 40MW Wholesale Order from Leading Internet Company for Its New Strategic IDC Campus

September 11, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio