Zero Day in Cleo File Transfer Software Exploited En Masse
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-50623 | Unauthenticated RCE via Unrestricted File Upload in Cleo Harmony, VLTrader, LexiCom CVE-2024-50623 is an unrestricted file upload and download flaw (CWE-434) in Cleo's managed file transfer products — Harmony, VLTrader, and LexiCom — before version 5.8.0.21. It is reachable over the network with no authentication or user interaction (CVSS 9.8, AV:N/AC:L/PR:N), letting an attacker send crafted requests that upload arbitrary files to the server. The unrestricted upload leads to remote code execution, giving the attacker full control of the host for staging, data theft, or ransomware, while the download capability risks exposure of business files the server moves with trading partners. Any organization running these products is affected, and managed file transfer servers are typically internet-facing and handle sensitive B2B data. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2024-12-13 with ransomware use noted, EPSS assigns a 98.6% probability of exploitation within 30 days, and the Clop ransomware gang has claimed dozens of breaches (some disputed), including a confirmed breach at WK Kellogg. Do: Upgrade Harmony, VLTrader, and LexiCom to 5.8.0.21 or later per vendor instructions; if upgrading is not possible, apply vendor mitigations or discontinue use of the product, as CISA's KEV entry requires. Prioritize internet-exposed instances, hunt for indicators of compromise (unexpected file writes and execution on the transfer host, new accounts, suspicious outbound connections), and restrict the service to trusted partner networks. Given known ransomware use by Clop, any suspected compromise should trigger checks for lateral movement and staged exfiltration of transferred files. | 9.8 | 99% | KEV ransomware |
| moderate≈1,000–3,000 internet-exposed Cleo servers (tens of thousands of enterprise deployments) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 5.8.0.21 | urging customers to upgrade to the latest product version (5.8.0.21) “to address additional discovered potential attack vectors |
Full article451 words · extracted from infosecurity-magazine.com · click to collapse
Security researchers have warned customers of the popular file transfer software vendor Cleo that a zero-day vulnerability is currently being exploited in the wild to steal their data.
Security vendor Huntress was the first to publicize the attacks on Monday, claiming that the remote code execution (RCE) bug CVE-2024-50623 affects the Cleo Harmony, VLTrader and LexiCom products.
It apparently stems from an incomplete vendor patch released in October that the threat actors were able to bypass.
“From our telemetry, we’ve discovered at least 10 businesses whose Cleo servers were compromised with a notable uptick in exploitation observed on December 8 around 07:00 UTC. After some initial analysis, however, we have found evidence of exploitation as early as December 3,” said Huntress.
“The majority of customers that we saw compromised deal with consumer products, food industry, trucking, and shipping industries. There are still several other companies outside of our immediate view who are potentially compromised as well.”
Read more on attacks on file transfer software: Clop Ransomware Group Exploits GoAnywhere MFT Flaw
Cleo released an advisory on Tuesday, urging customers to upgrade to the latest product version (5.8.0.21) “to address additional discovered potential attack vectors of the vulnerability.” However, Huntress claimed that even this patch was “insufficient” against exploits it saw in the wild.
Cleo’s latest communication, issued soon after, noted that products up to version 5.8.0.23 are affected. It features a link for customers so they can take “immediate action” to mitigate the flaw.
“Cleo has identified an unauthenticated malicious hosts vulnerability (CVE pending) that could lead to remote code execution,” it stated.
At the time of writing, a patch had not been released by the vendor for this new exploit, but one is thought to be pending.
Urgent Action Required
Rapid7 advised Cleo customers to remove affected products from the public internet and ensure they are put behind a firewall.
“Per Huntress’s investigation, disabling Cleo’s Autorun Directory, which allows command files to be automatically processed, may also prevent the latter part of the attack chain from being executed,” it added.
“Huntress’s blog has several descriptions of post-exploitation activity, including attack chain artifacts, commands run and files dropped for persistence. Rapid7 recommends that affected customers review these indicators and investigate their environments for suspicious activity dating back to at least December 3 2024.”
The campaign has echoes of previous efforts by the notorious Clop cybercrime group, which targeted managed file transfer software products from MOVEit, GoAnywhere and Accellion FTA with zero-day exploits, in order to steal and hold customer data to ransom.
Unconfirmed reports suggest that, this time around, the Termite group – previously responsible for an attack on Blue Yonder – may be behind the zero-day campaign.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/zero-day-cleo-file-transfer/