216.73.216.233

Cleo Software Actively Being Exploited in the Wild

· Published 10/12/2024 11:40 · Modified 10/12/2024 15:03

Export JSON

Essential information

Published
10/12/2024 11:40
Modified
10/12/2024 15:03
Tags
2024-12-10 CVE-2024-50623 cleo file transfer software harmony lexicom vltransfer vulnerability
Related entities
4 observables, 11 techniques (mitre), 3 others

Description

A critical in 's , , and software, used for file transfer management, is being actively exploited. The flaw allows unauthenticated remote code execution, affecting all versions up to and including 5.8.0.21. Attackers are exploiting this to drop malicious files, execute PowerShell commands, and gain persistence on affected systems. The attack chain involves placing files in the 'autorun' directory and leveraging the software's import functionality. Post-exploitation activities include domain reconnaissance and potential Active Directory enumeration. Multiple businesses, particularly in consumer products, food industry, trucking, and shipping sectors, have been compromised. Huntress researchers have developed a proof-of-concept and are working with to address the issue.

External references