SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-57727

SimpleHelp Path Traversal Vulnerability

KEVHIGH 7.5EPSS 95.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 March 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
95.15% probability · 100th percentile
CISA KEV
Listed 13 February 2025 · due 6 March 2025 · used in ransomware campaigns
Weakness
CWE-22
Affected
simple-help/simplehelp
Source
cve@mitre.org

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://simple-help.com/kb---security-vulnerabilities-01-2025 ; Additional CISA Mitigation Instructions: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-163a ; https://nvd.nist.gov/vuln/detail/CVE-2024-57727

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.