logo

CVE-2024-55956: Zero-Day Vulnerability in Cleo Software Could Lead to Data Theft

ID: d6337e14-05a5-5b2b-8fa5-d2625527273e

STIX ID: report--d6337e14-05a5-5b2b-8fa5-d2625527273e

Feed Name: Cybereason Blog

Threat Score
90/100

Date Published: 2024-12-17

Date Updated: 2026-04-27

Author: Cybereason Consulting Team

...
...

A zero-day vulnerability (CVE-2024-55956) affecting Cleo Harmony, VLTrader, and LexiCom allows unauthenticated arbitrary command execution via the Autorun directory; CL0P has claimed and begun exploiting this flaw for data theft, the report provides numerous IOCs (Cobalt Strike server IPs, a Java loader SHA-256, autorun filenames, and XML artifacts) and recommends immediate upgrade to Cleo version 5.8.0.24, disabling Autorun if upgrade is not possible, removing affected systems from the public internet, and conducting forensic investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.