Today > 6 Critical | 25 High | 23 Medium vulnerabilities   -   You can now download lists of IOCs here!

New Cleo zero-day RCE flaw exploited in data theft attacks

Dec. 11, 2024, 11:33 a.m.

Description

A critical zero-day vulnerability in Cleo's managed file transfer software is being actively exploited by hackers to breach corporate networks and steal data. The flaw affects Cleo LexiCom, VLTrader, and Harmony products, allowing unrestricted file upload and downloads leading to remote code execution. It bypasses a previous fix for CVE-2024-50623. Exploitation began on December 3, 2024, with a significant increase on December 8. The attacks involve writing malicious files into the 'autorun' directory, which are then processed automatically, executing PowerShell commands and downloading additional payloads. At least ten organizations have been impacted, with 390 potentially vulnerable servers identified globally. Users are advised to take immediate mitigation steps, including moving exposed systems behind firewalls and disabling the autorun feature.

Date

Published: Dec. 11, 2024, 2:51 a.m.

Created: Dec. 11, 2024, 2:51 a.m.

Modified: Dec. 11, 2024, 11:33 a.m.

Attack Patterns

Termite

Termite

T1505.003

T1059.001

T1070.004

T1105

T1071

T1046

T1190

T1133

T1078