SimpleHelp remote support software v5.5.7 and earlier contains a zip slip vulnerability allowing admin users to upload arbitrary files anywhere on the file system and execute code. This remote support software is commonly deployed as internet-facing infrastructure for IT support organizations.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-01-15
Added to CISA KEV: 2026-04-24 464 DAYS BETWEEN CVE AND KEV
CVE-2024-57728 is a critical path traversal vulnerability affecting SimpleHelp remote support software versions 5.5.7 and earlier [2].
CVE-2024-57728 is a 'path traversal' vulnerability with a CVSSv3 score of 7.2. If exploited, a remote, authenticated attacker with administrator privileges could upload arbitrary files anywhere on the file system, which could allow the attacker to execute arbitrary code in the context of the SimpleH…
CVE-2024-57728 Detail. Description. SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file ...
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file.