/Vulnerability Library

SimpleHelp <= 5.5.7 - Arbitrary File Upload

CVE-2024-57728
Verified

Description

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. This template is a version-based check: it reads the version banner exposed by the vendor's own /allversions page and flags branches that predate the January 2025 fixes.

Severity

High

CVSS Score

7.2

Exploit Probability

65%

Affected Product

simplehelp

Published Date

August 20, 2026

Template Author

popy21

CVE-2024-57728.yaml
7.2Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2024-57728
CWE ID:
cwe-59

References

https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlierhttps://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/https://guides.simple-help.com/kb---checking-the-version-and-build-of-your-simplehelp-serverhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57728https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze-on-vulnerable-web-facing-assets-in-high-tempo-medusa-ransomware-operations/https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-dragonforcehttps://nvd.nist.gov/vuln/detail/CVE-2024-57728

Remediation Steps

Upgrade SimpleHelp to 5.5.8 or later (or apply the vendor's 070125 patch to the 5.4.10 and 5.3.9 branches), then rotate all administrator and technician passwords and restrict the source IP addresses allowed to log in.