/00 — boot sequence

Hello.

Article

BeyondTrust Patches Critical Unauthenticated RCE Flaws (CVE-2024-12356) in Remote Support and PRA

July 10, 2026•5 min read
security vulnerability beyondtrust rce cve-2024-12356 critical

BeyondTrust has released emergency security updates to address a critical command injection vulnerability in its Privileged Remote Access (PRA) and Remote Support (RS) products, tracked as CVE-2024-12356. With a CVSS score of 9.8 out of 10, this is among the most severe vulnerabilities disclosed in enterprise remote access software this year.

The vulnerability allows a remote, unauthenticated attacker to inject arbitrary commands that execute with the privileges of a site user — requiring no credentials, no user interaction, and no special conditions. Organizations using on-premises deployments of these products should treat patch application as a matter of hours, not days.

Vulnerability Details

FieldValue
CVE IDCVE-2024-12356
CVSS Score9.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
TypeCommand Injection → Remote Code Execution
Authentication RequiredNone — unauthenticated exploit
Attack VectorNetwork-based
Products AffectedBeyondTrust Remote Support (RS) & Privileged Remote Access (PRA) — on-premises deployments
Researcher DiscoveryTracked as CVE-2024-12356 by BeyondTrust
StatusActively exploited in the wild (per Rescana)

The CVSS vector paints a stark picture: every single metric is at the maximum severity level. Network-based (AV:N), low complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), and full impact on confidentiality, integrity, and availability (C:H/I:H/A:H).

Impact Assessment

BeyondTrust Remote Support and PRA are enterprise staples for remote access, session management, and privileged credential vaulting. A successful exploit gives an attacker:

  • Full remote control of the BeyondTrust appliance and its managed sessions
  • Access to all recorded sessions — including credentials, keystrokes, and screen captures from privileged sessions
  • Lateral movement vector — the appliance sits at the intersection of IT administration, remote support, and privileged access, making it an ideal pivot point into the internal network
  • Persistence — the attacker can inject persistent backdoors into the BeyondTrust deployment

The "Active Exploitation Alert" from Rescana on July 7 indicates that threat actors have already developed and deployed exploits targeting this vulnerability. The July 9 SC Media report further confirmed active exploitation attempts observed in the wild.

Affected Systems

If your organization runs on-premises deployments of these BeyondTrust products, you are affected:

  • BeyondTrust Remote Support (RS) — on-premises versions prior to the July 2026 security update
  • BeyondTrust Privileged Remote Access (PRA) — on-premises versions prior to the July 2026 security update

How to check if you are affected:

  1. Log into your BeyondTrust administration console
  2. Navigate to Support → About or System → Version Information
  3. Compare your build number against the patched versions listed in the BeyondTrust security advisory
  4. Check the BeyondTrust support portal for the latest hotfix and security patch notifications

Note: BeyondTrust's cloud/SaaS offerings may not be affected — the advisory specifically addresses on-premises deployments. Check with BeyondTrust support to confirm your deployment model.

Mitigation and Patching

  1. Apply the July 2026 security update from the BeyondTrust support portal immediately. This is the only complete fix for CVE-2024-12356
  2. If immediate patching is not possible, consider temporarily restricting network access to the BeyondTrust appliances to trusted IP ranges only
  3. Review all active remote support sessions for unauthorized or suspicious connections
  4. Audit appliance logs for unusual command execution patterns or unexpected administrative actions
  5. Rotate all credentials that pass through the BeyondTrust appliance, as they may have been intercepted if the appliance was compromised
  6. Enable multi-factor authentication on the BeyondTrust admin console as an additional layer of defense

Detection

Security teams should look for these indicators of compromise:

  • Unexpected user accounts created on the BeyondTrust appliance or in connected directories
  • Unusual command execution in BeyondTrust logs — especially commands that differ from typical remote support patterns
  • Outbound connections from the BeyondTrust appliance to unknown IP addresses
  • Modified or new BeyondTrust configuration files
  • Session recordings showing unexpected administrative actions or credential access

Organizations with SIEM/SOAR platforms should create detection rules specifically for CVE-2024-12356 exploitation patterns, focusing on anomalous command injection attempts against the BeyondTrust management interface.

Frequently Asked Questions

Does this vulnerability require authentication? No. CVE-2024-12356 can be exploited by an unauthenticated attacker over the network. This makes it significantly more dangerous than vulnerabilities requiring valid credentials.

Can this be exploited remotely? Yes. The attack vector is network-based (AV:N). Any attacker who can reach the BeyondTrust appliance over the network can attempt exploitation.

Is there a patch available? Yes. BeyondTrust released a security update in July 2026. Organizations should apply it immediately.

Does this affect BeyondTrust cloud/SaaS? The advisory primarily targets on-premises deployments. Check BeyondTrust's official communication for cloud service impacts.

What is the worst-case scenario? An attacker achieving unauthenticated RCE on a BeyondTrust PRA or RS appliance gains access to all privileged sessions and credentials managed through the platform, enabling a full-scale enterprise compromise.

How quickly should we patch? Immediately. With a CVSS score of 9.8 and confirmed active exploitation, this is a maximum-priority emergency. Every hour of delay increases the probability of compromise.

Key Takeaways

  • CVE-2024-12356 is a CVSS 9.8 critical command injection vulnerability in BeyondTrust Remote Support and PRA products
  • No authentication is required — a network-accessible attacker can achieve full RCE
  • Active exploitation has been confirmed by Rescana and SC Media, with multiple threat actors observed targeting the flaw
  • All on-premises deployments must be patched immediately with the July 2026 security update
  • Impact includes full compromise of privileged sessions, credential vaults, and potential lateral movement across the enterprise
  • Organizations should audit BeyondTrust logs for signs of compromise and rotate credentials that have passed through the appliance

Conclusion

CVE-2024-12356 represents a critical threat to organizations relying on BeyondTrust for privileged access management and remote support. With a perfect-storm CVSS of 9.8 — unauthenticated, network-based, no user interaction needed — and confirmed active exploitation, this vulnerability demands an immediate response from security teams.

The lesson is clear: remote access and privileged management software, by their very nature, are high-value targets. When vulnerabilities emerge in these platforms, the window for patching is measured in days, not weeks. Organizations should not only patch but also treat the incident as a potential breach requiring thorough forensic investigation.


Sources: NVD — CVE-2024-12356 | The Hacker News | Rescana Active Exploitation Alert | BleepingComputer | SC Media

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links