BeyondTrust Product Security Update Advisory (CVE-2024-12356)

Overview

 

An update has been released to address vulnerabilities in BeyondTrust Products. Users of the affected versions are advised to update to the latest version.
 

 

Affected Products

 

CVE-2024-12356

  • Privileged Remote Access (PRA) versions: ~ 24.3.1 (inclusive)
  • Remote Support (RS) versions: ~ 24.3.1 (inclusive)

 

 

Resolved Vulnerabilities

 

Vulnerability that could allow an unauthenticated attacker to inject commands running as the site user (CVE-2024-12356)

 

Vulnerability Patches

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-12356

  • Privileged Remote Access (PRA) version: PRA Patch BT24-10-ONPREM1
  • Privileged Remote Access (PRA) version: PRA Patch BT24-10-ONPREM2

 

  • Remote Support (RS) version: RS patch BT24-10-ONPREM1
  • Remote Support (RS) version: RS Patch BT24-10-ONPREM2

 

 

Referenced Sites

 

[1] CVE-2024-12356 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-12356

[2] Advisory ID: BT24-10

https://www.beyondtrust.com/trust-center/security-advisories/bt24-10