Threat Intelligence / CVE / CVE-2024-12686
CVE-2024-12686
CISA KEVA vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
CVSS v3 vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-78
Threats tracking this CVE
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-12686
- https://www.beyondtrust.com/trust-center/security-advisories/bt24-11
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-12686
Full detection coverage & IOCs for threats exploiting CVE-2024-12686 are available via the Threadlinqs MCP server (Purple tier). View plans →