CVE List

CVE-2024-55956

Severe 9.8

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Published December 13, 2024.

Affected software

Get alerts for Cleo Harmony

Reference links