Critical severity9.8NVD Advisory· Published Jun 16, 2025· Updated Jun 17, 2026
CVE-2025-5309
CVE-2025-5309
Description
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
Affected products
7cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:beyondtrust:privileged_remote_access:*:*:*:*:*:*:*:*range: >=24.2.2,<=24.2.4
- cpe:2.3:a:beyondtrust:privileged_remote_access:25.1.1:*:*:*:*:*:*:*
cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:beyondtrust:remote_support:*:*:*:*:*:*:*:*range: >=24.2.2,<=24.2.4
- cpe:2.3:a:beyondtrust:remote_support:25.1.1:*:*:*:*:*:*:*
- (no CPE)
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 24.2.2
Patches
Vulnerability mechanics
References
1- www.beyondtrust.com/trust-center/security-advisories/bt25-04nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.