Critical severity9.8CISA KEVNVD Advisory· Published Dec 13, 2024· Updated Aug 5, 2026
CVE-2024-55956
CVE-2024-55956
Description
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- Cleo Harmony/Cleo Harmonydescription
Patches
Vulnerability mechanics
References
4- www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wildnvdExploitThird Party Advisory
- support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Advisory-CVE-PendingnvdVendor Advisory
- support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-UpdatenvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- Risky Business #775 -- Cl0p is back, SEC hack disclosures disappointRisky Business · Dec 18, 2024