New Cleo zero-day RCE flaw exploited in data theft attacks
Dec. 11, 2024, 11:33 a.m.
Tags
External References
Description
A critical zero-day vulnerability in Cleo's managed file transfer software is being actively exploited by hackers to breach corporate networks and steal data. The flaw affects Cleo LexiCom, VLTrader, and Harmony products, allowing unrestricted file upload and downloads leading to remote code execution. It bypasses a previous fix for CVE-2024-50623. Exploitation began on December 3, 2024, with a significant increase on December 8. The attacks involve writing malicious files into the 'autorun' directory, which are then processed automatically, executing PowerShell commands and downloading additional payloads. At least ten organizations have been impacted, with 390 potentially vulnerable servers identified globally. Users are advised to take immediate mitigation steps, including moving exposed systems behind firewalls and disabling the autorun feature.
Date
Published: Dec. 11, 2024, 2:51 a.m.
Created: Dec. 11, 2024, 2:51 a.m.
Modified: Dec. 11, 2024, 11:33 a.m.
Attack Patterns
Termite
Termite
T1505.003
T1059.001
T1070.004
T1105
T1071
T1046
T1190
T1133
T1078