BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
| Vendor | Product | Versions |
|---|---|---|
| beyondtrust | privileged_remote_access | < 25.1, < 25.3.2 |
Added CWE-20 and identified a new IOC related to the threat actor Storm-1175.
Initial creation