← Back to CVE List
Vulnerability Intelligence Report
Remote Support & Privileged Remote Access server side template injection

CVE-2025-5309

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

No Active Exploit Signals
CVSS Base Score
8.6
HIGH
EPSS Probability:0.88%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-94 ↗CWE-94 Improper Control of Generation of Code ('Code Injection')

Affected Products & Versions

Vendor Product Affected Versions
BeyondTrust Remote support & Privileged Remote Access 24.2.2 <= 24.2.4 (affected), 24.3.1 <= 24.3.3 (affected), 25.1.1 (affected)
BeyondTrust Remote Support(RS) & Privileged Remote Access(PRA) 24.2.2 <= 24.2.4 (affected), 24.3.1 <= 24.3.4 (affected), 25.1.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.875%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityBeyondTrust Inc. · Vendor · USA
Reserved2025-05-28T17:50:50
Published2025-06-16T16:06:14
Last Updated2026-02-26T17:50:35

LINK COPIED TO CLIPBOARD