SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-57728

SimpleHelp Path Traversal Vulnerability

KEVHIGH 7.2EPSS 6.98%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 8 May 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
6.98% probability · 94th percentile
CISA KEV
Listed 24 April 2026 · due 8 May 2026 · used in ransomware campaigns
Weakness
CWE-59, CWE-22
Affected
simple-help/simplehelp
Source
cve@mitre.org

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57728

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.