CVE-2024-57727
simple-help simplehelp
Published 15 Jan 2025 · updated 4 Aug 2026 · Analyzed
7.5 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 13 Feb 2025, with a remediation deadline of 6 Mar 2025 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
References
- simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier · Release Notes
- www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/ · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57727 · US Government Resource