CVE-2024-55956

cleo harmony, cleo lexicom, cleo vltrader

Published 13 Dec 2024 · updated 5 Aug 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 17 Dec 2024, with a remediation deadline of 7 Jan 2025 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

References