Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • BT25-04 current page
Link copied

BT25-04

Security Advisories

Advisory ID: BT25-04

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
  • CVSSv4 Score: 8.6
  • CVSSv4 Vector AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • Severity: High
  • Issue Date: 2025-06-16
  • Updated On: 2025-06-16
  • CVE(s): CVE-2025-5309
  • CWE CWE-94
  • Synopsis: RCE Via Server-Side Template Injection
  • Impacted: Product Remote Support and Privileged Remote Access

Summary

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

Details

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Remote Support and Privileged Remote Access components do not properly escape input intended for the template engine, leading to a potential template injection vulnerability. This flaw may allow an attacker to execute arbitrary code in the context of the server. Notably, in the case of Remote Support, exploitation does not require authentication.

Mitigation

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

A patch has been applied to all RS/PRA cloud customers as of June 16, 2025 that remediates this vulnerability.

On-premise customers of RS/PRA should apply the patch if their instance is not subscribed to automatic updates in their /appliance interface.

Remote Support

If the patch cannot be applied, the following options for the Public Site can help mitigate exploitation of this vulnerability:

  • Enable SAML authentication for the Public Portal
  • Enforce session key usage by:
    • Ensuring Session Keys are enabled
    • Disabling the Representative List
    • Disabling the Issue Submission Survey

Privileged Remote Access

If you are on an affected version, apply the appropriate patch.

Affected Versions

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Product Version
Remote Support 24.2.2 to 24.2.4, 24.3.1 to 24.3.3, and 25.1.1
Privileged Remote Access 24.2.2 to 24.2.4, 24.3.1 to 24.3.3, and 25.1.1

Fixed Versions

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Product Version
Remote Support 24.2.2 to 24.2.4 with HELP-10826-2 Patch
Remote Support 24.3.1 to 24.3.3 with HELP-10826-2 Patch
Remote Support 24.3.4 and any future 24.3.x release
Remote Support 25.1.1 with HELP-10826-1 Patch
Privileged Remote Access 25.1.2 and above
Privileged Remote Access 24.2.2 to 24.2.4 with HELP-10826-2 Patch
Privileged Remote Access 24.3.1 to 24.3.3 with HELP-10826-2 Patch
Privileged Remote Access 25.1.1 with HELP-10826-1 Patch

References

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

https://www.cve.org/cverecord?id=CVE-2025-5309

https://nvd.nist.gov/vuln/detail/CVE-2025-5309

https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0022524

Acknowledgements

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

We would like to thank Jorren Geurts of Resillion for reporting this vulnerability responsibly.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.