Vulnary
← back to the feed
Critical· 9.8actively exploitedofficial fix available

CVE-2024-55956

An unauthenticated attacker can run arbitrary Bash or PowerShell commands on the host by exploiting the default Autorun directory settings in Cleo Harmony, VLTrader, and LexiCom versions before 5.8.0.24. This allows full control over the system. The vulnerability is critical with a CVSS score of 9.8.

publishedDec 13, 2024
last modifiedAug 5, 2026
sourcesNVD · CISA-KEV
severity · cvss
9.8
critical · how bad it is
exploitation · epss
94%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Cleo Harmony, Cleo VLTrader, and Cleo LexiCom versions prior to 5.8.0.24.

02

Real-world impact

An attacker can execute arbitrary commands on the host, giving them full control over the system, including data theft, modification, or destruction.

03

Why this severity

The CVSS score is high because the vulnerability allows remote unauthenticated execution of arbitrary code with no user interaction, giving complete compromise of confidentiality, integrity, and availability.

04

What to do about it

official fix available
recommended steps
  1. 01Follow the vendor’s mitigation instructions for Cleo Harmony, VLTrader, and LexiCom before 5.8.0.24.
  2. 02If no mitigation is available, discontinue use of the product.

CISA KEV required action

05

Timeline

  1. Dec 13, 2024 · Dec 13, 2024
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Dec 17, 2024 · Dec 17, 2024
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  3. Jan 7, 2025 · Jan 7, 2025
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
  4. Aug 5, 2026 · 20h ago
    Advisory updated
    The NVD record was last revised.
  5. Aug 5, 2026 · 18h ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →