In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.
This Cyber News was published on www.tenable.com. Publication date: Fri, 13 Dec 2024 00:00:00 +0000