Stephen Fewer

Stephen Fewer

@stephenfewer · Twitter ·

We have published our @rapid7 analysis of the new Cleo vuln, now known as CVE-2024-55956. An unauthenticated file write affecting LexiCom, VLTrader, and Harmony versions 5.8.0.23 and below, that can be leveraged to achieve unauth RCE. Full analysis here: https://attackerkb.com/topics/geR0H8dgrE/cve-2024-55956/rapid7-analysis

Post media