HomeCyber BalkansCleo patches file transfer zero-day vulnerability under attack

Cleo patches file transfer zero-day vulnerability under attack

Published on

spot_img

Cleo, a leading managed file transfer (MFT) provider, recently released a patch to address a zero-day vulnerability in their Harmony, LexiCom, and VLTrader products. This vulnerability, which has not yet been assigned a CVE number, was originally patched in late October but was found to still be exploitable by threat actors.

The discovery of this vulnerability, known as CVE-2024-50623, led to concerns about unrestricted file upload and download capabilities in Cleo’s products. Despite a previous patch release, security researchers found that the vulnerability was still being actively exploited, prompting Cleo to take further action.

In response to these ongoing security concerns, Cleo issued a new patch, version 5.8.0.24, on Wednesday evening. This patch specifically addresses the critical vulnerability that allowed for unrestricted file upload and download, as well as the execution of malicious host definitions. Cleo advised customers to apply the patch immediately to protect their systems from potential attacks.

In a security advisory, Cleo explained that the vulnerability could allow an unauthenticated user to import and execute arbitrary bash or PowerShell commands on the host system. By leveraging the default settings of the Autorun directory, attackers could exploit this vulnerability to gain unauthorized access to Cleo’s products.

Security researcher John Hammond of Huntress Labs, who has been closely monitoring the situation, noted that the new patch seems to be effective in preventing the exploitation of the zero-day vulnerability. However, concerns remain about the potential involvement of threat actors, such as the Termite ransomware group, in exploiting Cleo’s MFT products.

Despite speculation about specific threat groups, experts like Christiaan Beek of Rapid7 cautioned against jumping to conclusions without verifiable evidence. Beek emphasized the importance of correlating technical indicators, tools, techniques, and past observations to accurately identify and assess security threats.

In response to the ongoing investigation into the zero-day vulnerability, Cleo has reassured customers that they are taking proactive measures to address the issue. The company has provided enhanced 24/7 customer support services to assist customers in applying the necessary patches and securing their systems against potential attacks.

As the situation continues to unfold, both Cleo and cybersecurity experts urge customers to stay informed and vigilant. By staying up to date on security bulletins and taking proactive measures to protect their systems, customers can mitigate the risks posed by zero-day vulnerabilities and potential threat actors.

In conclusion, the recent patch release by Cleo underscores the ongoing challenges of cybersecurity in today’s digital landscape. With zero-day vulnerabilities posing a constant threat to organizations’ data and systems, proactive measures and prompt patching are essential to safeguard against potential attacks.

Source link

Latest articles

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

 Fortinet on Wednesday said it observed "recent abuse" of a five-year-old security flaw in FortiOS...

More like this

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...