Cleo Releases Patches for Cleo MFT Zero-day Vulnerability
ID: b249989f-2e1a-5664-9458-a0715f2d0702
STIX ID: report--b249989f-2e1a-5664-9458-a0715f2d0702
Feed Name: Arctic Wolf
Arctic Wolf reported a zero-day remote code execution vulnerability in Cleo Managed File Transfer (MFT) products that allowed unauthenticated attackers to import and run arbitrary shell commands by abusing default Autorun directory settings; active exploitation was observed starting 7 December 2024, a proof-of-concept is available, and reports indicate possible use by Termite ransomware. Cleo released fixes in version 5.8.0.24 for Harmony, VLTrader, and Lexicom and recommends immediate patching or removing internet-exposed systems as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
