CVE-2024-55956

CRITICAL KEV RANSOMWARE NUCLEI

Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2024-55956 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added December 17, 2024, with confirmed use in ransomware campaigns. EIP tracks 1 public exploit from researchers including sfewer-r7, remmons-r7, including a Metasploit module exploits/multi/http/cleo_rce_cve_2024_55956. A Nuclei detection template is also available.

AI-analyzed exploit summary This Metasploit module exploits an unauthenticated file write vulnerability in Cleo LexiCom, VLTrader, and Harmony versions 5.8.0.23 and below, leading to remote code execution. It leverages XML-based configuration files to execute arbitrary commands via an autorun mechanism.

Description

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Exploits (1)

metasploit WORKING POC EXCELLENT
by sfewer-r7, remmons-r7 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/cleo_rce_cve_2024_55956.rb

This Metasploit module exploits an unauthenticated file write vulnerability in Cleo LexiCom, VLTrader, and Harmony versions 5.8.0.23 and below, leading to remote code execution. It leverages XML-based configuration files to execute arbitrary commands via an autorun mechanism.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Cleo LexiCom, VLTrader, and Harmony <= 5.8.0.23
No auth needed
Prerequisites: Network access to the target service (port 5080 by default) · Target software must be running and vulnerable
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Cleo Harmony < 5.8.0.24 - File Upload Vulnerability
CRITICALVERIFIEDby iamnoooob,rootxharsh,pdresearch
Shodan: Server: Cleo

Scores

CVSS v3 9.8
EPSS 0.9380
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2024-12-17
VulnCheck KEV 2024-12-10
InTheWild.io 2024-12-17
ENISA EUVD EUVD-2024-52864
Ransomware Use Confirmed
CWE
CWE-77
Status published
Products (3)
cleo/harmony < 5.8.0.24
cleo/lexicom < 5.8.0.24
cleo/vltrader < 5.8.0.24
Published Dec 13, 2024
KEV Added Dec 17, 2024
Tracked Since Feb 18, 2026