Arbitrary File Upload Vulnerability in SimpleHelp Remote Support Software
CVE-2024-57728

7.2HIGH

Key Information:

Vendor
SimpleHelp
Vendor
CVE Published:
15 January 2025

Badges

๐Ÿ’ฐ Ransomware๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

Summary

The SimpleHelp Remote Support Software, versions 5.5.7 and earlier, is susceptible to an arbitrary file upload vulnerability. This flaw allows admin users to upload specially crafted zip files, which can exploit a phenomenon known as 'zip slip'. By leveraging this vulnerability, malicious actors can potentially upload arbitrary files to any directory on the file system, leading to unauthorized code execution in the context of the server user, creating a serious security risk for businesses relying on this software. Users are advised to update to the latest version to mitigate the threat.

News Articles

SimpleHelp Remote Support Software Vulnerability Let Attackers Execute Remote Code

Researchers have disclosed three critical vulnerabilities in SimpleHelp, a widely used remote support software, that could allow attackers to compromise servers and client machines.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ’ฐ

    Used in Ransomware

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by CybersecurityNews

  • Vulnerability published

  • Vulnerability Reserved

.