// NEXUSVOID CYBER NEWS
<- ALL CYBER NEWS
Critical
BeyondTrust, auth bypass, privileged access, remote support, RCE, MSP
The Tool That Controls Access to Everything Just Had an Auth Bypass
BeyondTrust patched two critical auth-bypass flaws in its Remote Support and Privileged Remote Access products that let unauthenticated attackers take over installations. When the tool that controls access can itself be bypassed, it becomes a skeleton key.
There is a particular irony when the product that fails is the one whose entire job is to control access. BeyondTrust, whose Remote Support and Privileged Remote Access tools are used by help desks and administrators to reach into sensitive systems, has patched two critical flaws that let an unauthenticated attacker take control of vulnerable installations, as reported by The Hacker News.
An authentication bypass in this class of software is close to a worst case. These tools are, by design, connected to the crown jewels: the servers, workstations, and privileged sessions that everything else depends on. A remote support platform is a skeleton key, and a flaw that lets an outsider walk in without credentials hands that key to whoever finds it first.
The reason to move fast is not only the severity, it is the target profile. Remote access and support products have a track record of being hit quickly after disclosure, because the payoff is so high: one appliance can be the doorway to an entire managed estate, and for managed service providers, to their customers' estates as well. Attackers know exactly what these boxes are worth.
Apply BeyondTrust's updates immediately, and while you are there, confirm the appliances are not needlessly exposed to the open internet and review access logs for anything unfamiliar. Software that holds the keys deserves to be verified continuously, not trusted because of what it is named.
Sources: The Hacker News.