THREAT OPS › Threat News › [NVD] CVE-2024-55956 (CRITICAL 9.8) — In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
[NVD] CVE-2024-55956 (CRITICAL 9.8) — In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
CVE-2024-55956 CVSS: 9.8 CRITICAL Published: 2024-12-13T21:15:13.767
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
MITRE ATT&CK techniques
- PowerShellT1059.001
Indicators of compromise
- CVE-2024-55956cve
- 5.8.0.24ipv4
Original source: https://nvd.nist.gov/vuln/detail/CVE-2024-55956