Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » BeyondTrust releases urgent patch for critical vulnerability in PRA and RS products
Global Security

BeyondTrust releases urgent patch for critical vulnerability in PRA and RS products

AdminBy AdminDecember 18, 2024No Comments2 Mins Read
Critical Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 18, 2024Ravi LakshmananSaaS Security / Incident Response

A critical vulnerability

BeyondTrust has disclosed details of a critical security flaw in its Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to the execution of arbitrary commands.

Privileged Remote Access monitors, manages, and validates privileged accounts and credentials, offering internal, external, and third-party users zero-trust access to on-premises and cloud resources. Remote support allows support staff to securely connect to remote systems and mobile devices.

Vulnerability, tracked as CVE-2024-12356 (CVSS score: 9.8), was described as an instance of team introduction.

Cyber ​​security

“A critical vulnerability has been discovered in the Privileged Remote Access (PRA) and Remote Support (RS) products that could allow an unauthenticated attacker to issue commands that execute on behalf of a site user,” the company said in a statement. said in the consulting room.

An attacker could exploit the flaw by sending a malicious client request, effectively causing arbitrary operating systems to execute in the context of the site user.

The issue affects the following versions –

  • Privileged Remote Access (versions 24.3.1 and earlier) – Fixed in PRA patch BT24-10-ONPREM1 or BT24-10-ONPREM2
  • Remote support (versions 24.3.1 and earlier) – fixed in RS patch BT24-10-ONPREM1 or BT24-10-ONPREM2

A patch for the vulnerability has already been applied to cloud instances as of December 16, 2024. Users of local versions of the software are advised to apply the latest patches unless they are subscribed to automatic updates.

“If customers are running a version older than 22.1, they will need to upgrade to apply this patch,” BeyondTrust said.

Cyber ​​security

The company said the flaw was discovered during an ongoing forensic investigation that began after a “security incident” on December 2, 2024. involving “a limited number of Remote Support SaaS customers”.

“A root cause analysis of the Remote Support SaaS issue revealed that the API key for the Remote Support SaaS was compromised” — BeyondTrust saidadding that it “immediately revoked the API key, notified known affected customers, and suspended those instances the same day, providing alternative instances of the Remote Support SaaS to those customers.”

BeyondTrust also said it is still working to determine the cause and effect of the compromise in partnership with an unnamed “cybersecurity and forensics firm.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.