CVE-2024-55956
CRITICAL KEV RANSOMWARE NUCLEICleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution
Title source: metasploitExploitation Summary
CVE-2024-55956 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added December 17, 2024, with confirmed use in ransomware campaigns.
EIP tracks 1 public exploit from researchers including sfewer-r7, remmons-r7, including a Metasploit module exploits/multi/http/cleo_rce_cve_2024_55956.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file write vulnerability in Cleo LexiCom, VLTrader, and Harmony versions 5.8.0.23 and below, leading to remote code execution. It leverages XML-based configuration files to execute arbitrary commands via an autorun mechanism.
Description
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
Exploits (1)
This Metasploit module exploits an unauthenticated file write vulnerability in Cleo LexiCom, VLTrader, and Harmony versions 5.8.0.23 and below, leading to remote code execution. It leverages XML-based configuration files to execute arbitrary commands via an autorun mechanism.
Nuclei Templates (1)
Server: Cleo
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H