Arbitrary File Upload Vulnerability in SimpleHelp Remote Support Software
CVE-2024-57728
7.2HIGH
Key Information:
- Vendor
- SimpleHelp
- Status
- Vendor
- CVE Published:
- 15 January 2025
Badges
๐ฐ Ransomware๐พ Exploit Exists๐ฐ News Worthy
Summary
The SimpleHelp Remote Support Software, versions 5.5.7 and earlier, is susceptible to an arbitrary file upload vulnerability. This flaw allows admin users to upload specially crafted zip files, which can exploit a phenomenon known as 'zip slip'. By leveraging this vulnerability, malicious actors can potentially upload arbitrary files to any directory on the file system, leading to unauthorized code execution in the context of the server user, creating a serious security risk for businesses relying on this software. Users are advised to update to the latest version to mitigate the threat.
Get notified when SecurityVulnerability.io launches alerting ๐
Well keep you posted ๐ง
News Articles
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐ฐ
Used in Ransomware
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by CybersecurityNews
Vulnerability published
Vulnerability Reserved