BeyondTrust’s Patch Party: Fixing Remote Access Flaws Faster Than a Speeding Vulnerability
BeyondTrust patches a critical vulnerability in its PRA and RS products, CVE-2024-12356, which could let attackers command your system like a karaoke machine without the catchy tunes. Users should update faster than a caffeinated cheetah to avoid unauthorized hits on their devices.

Hot Take:
BeyondTrust seems to be playing a game of cybersecurity whack-a-mole with hackers, and this time they’ve finally managed to deliver a solid whack. Let’s just hope it doesn’t pop up elsewhere and startle the IT department into a collective heart attack!
Key Points:
- BeyondTrust released patches for a critical vulnerability in its PRA and RS products.
- The flaw, CVE-2024-12356, is an unauthenticated command injection bug with a CVSS score of 9.8.
- The security defect was identified during a forensic investigation into a security incident.
- Patches apply to PRA and RS versions 22.1.x and higher; cloud customers have already been patched.
- On-premise users must apply the patch manually unless subscribed to automatic updates.
Already a member? Log in here