CVE-2024-57727

simple-help simplehelp

Published 15 Jan 2025 · updated 4 Aug 2026 · Analyzed

7.5 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 13 Feb 2025, with a remediation deadline of 6 Mar 2025 for US federal agencies. It has been used in ransomware campaigns.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

References