CVE-2024-55956
An unauthenticated attacker can run arbitrary Bash or PowerShell commands on the host by exploiting the default Autorun directory settings in Cleo Harmony, VLTrader, and LexiCom versions before 5.8.0.24. This allows full control over the system. The vulnerability is critical with a CVSS score of 9.8.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Cleo Harmony, Cleo VLTrader, and Cleo LexiCom versions prior to 5.8.0.24.
Real-world impact
An attacker can execute arbitrary commands on the host, giving them full control over the system, including data theft, modification, or destruction.
Why this severity
The CVSS score is high because the vulnerability allows remote unauthenticated execution of arbitrary code with no user interaction, giving complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Follow the vendor’s mitigation instructions for Cleo Harmony, VLTrader, and LexiCom before 5.8.0.24.
- 02If no mitigation is available, discontinue use of the product.
CISA KEV required action
Timeline
- Dec 13, 2024 · Dec 13, 2024PublishedDisclosed and added to the National Vulnerability Database.
- Dec 17, 2024 · Dec 17, 2024Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jan 7, 2025 · Jan 7, 2025CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 5, 2026 · 20h agoAdvisory updatedThe NVD record was last revised.
- Aug 5, 2026 · 18h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- support.cleo.com/hc/en-us/articles/284081340…vendor advisory
- support.cleo.com/hc/en-us/articles/284081340…vendor advisory
- huntress.com/blog/threat-advisory-oh-no-…exploitthird party advisory
- cisa.gov/known-exploited-vulnerabili…us government resource