PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks

Rapid7 found that threat actors likely leveraged a previously undiscovered SQL injection vulnerability in PostgreSQL in addition to exploiting a zero-day vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products in December 2024.

The PostgreSQL interactive tool psql is impacted by the vulnerability, which is identified as CVE-2025-1094 (CVSS score: 8.1).

According to security researcher Stephen Fewer, an attacker can use the interactive tool’s capacity to execute meta-commands to accomplish arbitrary code execution (ACE) after successfully creating a SQL injection using read more about PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *