Unrated severityCISA KEVNVD Advisory· Published Dec 17, 2024· Updated Oct 21, 2025
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
CVE-2024-12356
Description
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
Affected products
2- BeyondTrust/Remote Supportv5Range: 0
- BeyondTrust/Privileged Remote Accessv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
1- Exploits and vulnerabilities in Q1 2026Securelist · May 7, 2026