Hackers who recently exploited a zero-day vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products likely also exploited another unknown SQL injection vulnerability in PostgreSQL.

The vulnerability is tracked as CVE-2025-1094 (CVSS score: 8.1) and affects the PostgreSQL interactive tool psql.
"An attacker who can cause SQL injection, via CVE-2025-1094, can achieve arbitrary code execution (ACE) by leveraging the interactive tool's ability to execute meta-commands," said security researcher Stephen Fewer.
See also: Palo Alto Networks fixes vulnerability in PAN-OS Software
Cybersecurity firm Rapid7 discovered the vulnerability while researching CVE-2024-12356, a recently patched bug in BeyondTrust software that allowed remote code execution without authentication.
Specifically, it found that “a successful exploitation of CVE-2024-12356 had to include an exploitation of CVE-2025-1094 in order to achieve remote code execution.”
See also: Hackers exploit old ThinkPHP and ownCloud vulnerabilities
PostgreSQL maintainers are patching the vulnerability in the following versions:
- PostgreSQL 17 (Fixed in 17.3)
- PostgreSQL 16 (Fixed in 16.7)
- PostgreSQL 15 (Fixed in 15.11)
- PostgreSQL 14 (Fixed in 14.16)
- PostgreSQL 13 (Fixed in 13.19)
The vulnerability is related to the way PostgreSQL handles invalid UTF-8 characters, allowing an attacker to exploit an SQL injection using a shortcut command “!”, which allows shell command execution.
“An attacker could exploit CVE-2025-1094 to execute this meta-command, thereby controlling the operating system shell command being executed,” Fewer said. “Alternatively, an attacker who can create SQL injection via CVE-2025-1094 could execute arbitrary SQL statements controlled by the attacker.”
See also: ICS Patch Tuesday: Addresses Schneider Electric and Siemens vulnerabilities

In today's ever-evolving digital landscape, cybersecurity is a critical aspect that all organizations must consider. The recent exploitation of the zero-day vulnerability in BeyondTrust Privileged Remote Access and Remote Support and the vulnerability in PostgreSQL highlight the need for constant vigilance and proactive measures to mitigate potential risks.
Regularly assessing and addressing any vulnerabilities, implementing strong access controls, and applying software updates are some key steps organizations can take to improve their security posture. Additionally, implementing a layered defense strategy and having an incident response plan can also help minimize the impact of successful attacks.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
