Zero-day vulnerability in Remote Support

OS Command Injection
CVE-2024-12686

Vulnerability details

Advisory: SB2025011424 - OS command injection in BeyondTrust Privileged Remote Access and Remote Support software

Vulnerable component: Remote Support

CVE-ID: CVE-2024-12686

CVSSv3 score: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Description:

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote privileged user can upload a specially crafted file on the system and execute arbitrary code as a site user. 

Note, the vulnerability is being exploited in the wild.