Junglewise Threat Intelligence

CVE-2024-55956: Cleo Multiple Products Unauthenticated File Upload Vulnerability

CVE-2024-55956 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-12-17

Technologies: Apple Multiple Products. Vendors: Apple.

Executive brief

Cleo Harmony, VLTrader, and LexiCom contain an unrestricted file upload vulnerability in the Autorun directory. An unauthenticated remote attacker can leverage default settings to upload and execute arbitrary Bash or PowerShell commands on the host system.

Affected products

  • Cleo Harmony before 5.8.0.24
  • Cleo VLTrader before 5.8.0.24
  • Cleo LexiCom before 5.8.0.24

Timeline

  • 2024-12-13: disclosed: Initial CVE publication by MITRE
  • 2024-12-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-12-17: exploited: Reported as actively being exploited in the wild by Huntress and CISA
  • 2024-12-20: patched: NVD analysis notes versions 5.8.0.24 and later are not affected

Related threats