216.73.216.226

New Cleo zero-day RCE flaw exploited in data theft attacks

· Published 11/12/2024 02:51 · Modified 11/12/2024 11:33

Export JSON

Essential information

Published
11/12/2024 02:51
Modified
11/12/2024 11:33
Tags
2024-12-11 CVE-2024-50623 cleo cleo harmony data theft lexicom rce termite vltrader zero-day
Related entities
1 intrusion sets (apt), 9 techniques (mitre), 1 malware

Description

A critical vulnerability in 's managed file transfer software is being actively exploited by hackers to breach corporate networks and steal data. The flaw affects , , and Harmony products, allowing unrestricted file upload and downloads leading to remote code execution. It bypasses a previous fix for . Exploitation began on December 3, 2024, with a significant increase on December 8. The attacks involve writing malicious files into the 'autorun' directory, which are then processed automatically, executing PowerShell commands and downloading additional payloads. At least ten organizations have been impacted, with 390 potentially vulnerable servers identified globally. Users are advised to take immediate mitigation steps, including moving exposed systems behind firewalls and disabling the autorun feature.

External references