Cleo Software Actively Being Exploited in the Wild CVE-2024-55956 | Huntress
ID: 825f9e71-bce6-57b6-8a4e-7b2b53a5bd18
STIX ID: report--825f9e71-bce6-57b6-8a4e-7b2b53a5bd18
Feed Name: Huntress Blog
Threat Score
Huntress warns of active exploitation against Cleo LexiCom, VLTrader, and Harmony (<= 5.8.0.21) via an arbitrary file-write vulnerability that allows autorun processing to execute encoded PowerShell and fetch JAR-based webshells for persistence; the vendor patch 5.8.0.21 was shown to be insufficient, multiple victims were observed, and Huntress published IOCs and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
