In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Cleo Harmony | cleo-harmony-upgrade-cve-2024-55956 | Dec 10, 2024 | Dec 10, 2024 | |
| Cleo Lexicom | cleo-lexicom-upgrade-cve-2024-55956 | Dec 10, 2024 | Dec 10, 2024 | |
| Cleo Vltrader | cleo-vltrader-upgrade-cve-2024-55956 | Dec 10, 2024 | Dec 10, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub