CVE-2024-55956
KEV RANSOMWARECRITICAL 9.8EPSS 94.0%
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 94.04% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-12-17, used in ransomware campaigns
- Nuclei
- critical · CWE-276
- Published
- 2024-12-13
- Updated
- 2026-08-05
Proof-of-concept exploits (2)
- https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exp…
- fl4m3-s/Cleo_Unauth_RCE2★ · 2025-01-14