BeyondTrust has released emergency security updates to address a critical command injection vulnerability in its Privileged Remote Access (PRA) and Remote Support (RS) products, tracked as CVE-2024-12356. With a CVSS score of 9.8 out of 10, this is among the most severe vulnerabilities disclosed in enterprise remote access software this year.
The vulnerability allows a remote, unauthenticated attacker to inject arbitrary commands that execute with the privileges of a site user — requiring no credentials, no user interaction, and no special conditions. Organizations using on-premises deployments of these products should treat patch application as a matter of hours, not days.
Vulnerability Details
| Field | Value |
|---|---|
| CVE ID | CVE-2024-12356 |
| CVSS Score | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Type | Command Injection → Remote Code Execution |
| Authentication Required | None — unauthenticated exploit |
| Attack Vector | Network-based |
| Products Affected | BeyondTrust Remote Support (RS) & Privileged Remote Access (PRA) — on-premises deployments |
| Researcher Discovery | Tracked as CVE-2024-12356 by BeyondTrust |
| Status | Actively exploited in the wild (per Rescana) |
The CVSS vector paints a stark picture: every single metric is at the maximum severity level. Network-based (AV:N), low complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N), and full impact on confidentiality, integrity, and availability (C:H/I:H/A:H).
Impact Assessment
BeyondTrust Remote Support and PRA are enterprise staples for remote access, session management, and privileged credential vaulting. A successful exploit gives an attacker:
- Full remote control of the BeyondTrust appliance and its managed sessions
- Access to all recorded sessions — including credentials, keystrokes, and screen captures from privileged sessions
- Lateral movement vector — the appliance sits at the intersection of IT administration, remote support, and privileged access, making it an ideal pivot point into the internal network
- Persistence — the attacker can inject persistent backdoors into the BeyondTrust deployment
The "Active Exploitation Alert" from Rescana on July 7 indicates that threat actors have already developed and deployed exploits targeting this vulnerability. The July 9 SC Media report further confirmed active exploitation attempts observed in the wild.
Affected Systems
If your organization runs on-premises deployments of these BeyondTrust products, you are affected:
- BeyondTrust Remote Support (RS) — on-premises versions prior to the July 2026 security update
- BeyondTrust Privileged Remote Access (PRA) — on-premises versions prior to the July 2026 security update
How to check if you are affected:
- Log into your BeyondTrust administration console
- Navigate to Support → About or System → Version Information
- Compare your build number against the patched versions listed in the BeyondTrust security advisory
- Check the BeyondTrust support portal for the latest hotfix and security patch notifications
Note: BeyondTrust's cloud/SaaS offerings may not be affected — the advisory specifically addresses on-premises deployments. Check with BeyondTrust support to confirm your deployment model.
Mitigation and Patching
- Apply the July 2026 security update from the BeyondTrust support portal immediately. This is the only complete fix for CVE-2024-12356
- If immediate patching is not possible, consider temporarily restricting network access to the BeyondTrust appliances to trusted IP ranges only
- Review all active remote support sessions for unauthorized or suspicious connections
- Audit appliance logs for unusual command execution patterns or unexpected administrative actions
- Rotate all credentials that pass through the BeyondTrust appliance, as they may have been intercepted if the appliance was compromised
- Enable multi-factor authentication on the BeyondTrust admin console as an additional layer of defense
Detection
Security teams should look for these indicators of compromise:
- Unexpected user accounts created on the BeyondTrust appliance or in connected directories
- Unusual command execution in BeyondTrust logs — especially commands that differ from typical remote support patterns
- Outbound connections from the BeyondTrust appliance to unknown IP addresses
- Modified or new BeyondTrust configuration files
- Session recordings showing unexpected administrative actions or credential access
Organizations with SIEM/SOAR platforms should create detection rules specifically for CVE-2024-12356 exploitation patterns, focusing on anomalous command injection attempts against the BeyondTrust management interface.
Frequently Asked Questions
Does this vulnerability require authentication? No. CVE-2024-12356 can be exploited by an unauthenticated attacker over the network. This makes it significantly more dangerous than vulnerabilities requiring valid credentials.
Can this be exploited remotely? Yes. The attack vector is network-based (AV:N). Any attacker who can reach the BeyondTrust appliance over the network can attempt exploitation.
Is there a patch available? Yes. BeyondTrust released a security update in July 2026. Organizations should apply it immediately.
Does this affect BeyondTrust cloud/SaaS? The advisory primarily targets on-premises deployments. Check BeyondTrust's official communication for cloud service impacts.
What is the worst-case scenario? An attacker achieving unauthenticated RCE on a BeyondTrust PRA or RS appliance gains access to all privileged sessions and credentials managed through the platform, enabling a full-scale enterprise compromise.
How quickly should we patch? Immediately. With a CVSS score of 9.8 and confirmed active exploitation, this is a maximum-priority emergency. Every hour of delay increases the probability of compromise.
Key Takeaways
- CVE-2024-12356 is a CVSS 9.8 critical command injection vulnerability in BeyondTrust Remote Support and PRA products
- No authentication is required — a network-accessible attacker can achieve full RCE
- Active exploitation has been confirmed by Rescana and SC Media, with multiple threat actors observed targeting the flaw
- All on-premises deployments must be patched immediately with the July 2026 security update
- Impact includes full compromise of privileged sessions, credential vaults, and potential lateral movement across the enterprise
- Organizations should audit BeyondTrust logs for signs of compromise and rotate credentials that have passed through the appliance
Conclusion
CVE-2024-12356 represents a critical threat to organizations relying on BeyondTrust for privileged access management and remote support. With a perfect-storm CVSS of 9.8 — unauthenticated, network-based, no user interaction needed — and confirmed active exploitation, this vulnerability demands an immediate response from security teams.
The lesson is clear: remote access and privileged management software, by their very nature, are high-value targets. When vulnerabilities emerge in these platforms, the window for patching is measured in days, not weeks. Organizations should not only patch but also treat the incident as a potential breach requiring thorough forensic investigation.
Sources: NVD — CVE-2024-12356 | The Hacker News | Rescana Active Exploitation Alert | BleepingComputer | SC Media
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.