CVE-2024-12686
high-risk
Published 2024-12-18
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
Do I need to act?
!
31.5% chance of exploitation in next 30 days
EPSS score — higher than 68% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.6/10
Medium
NETWORK
/ HIGH complexity
Affected Products (2)
Affected Vendors
References (3)
Third Party Advisory
https://nvd.nist.gov/vuln/detail/CVE-2024-12686
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-...
50
/ 100
high-risk
Severity
20/34 · Moderate
Exploitability
23/34 · High
Exposure
7/34 · Low