module
Cleo LexiCom, VLTrader, and Harmony Unauthenticated Remote Code Execution
Disclosed | Created |
---|---|
12/09/2024 | 01/16/2025 |
Disclosed
12/09/2024
Created
01/16/2025
Description
This module exploits an unauthenticated file write vulnerability in Cleo LexiCom, VLTrader, and Harmony
versions 5.8.0.23 and below.
versions 5.8.0.23 and below.
Authors
sfewer-r7remmons-r7
Platform
Java,Linux,Unix,Windows
Architectures
java, cmd
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:
msf > use exploit/multi/http/cleo_rce_cve_2024_55956 msf /(6) > show actions ...actions... msf /(6) > set ACTION < action-name > msf /(6) > show options ...show and set options... msf /(6) > run

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.