Junglewise Threat Intelligence

CVE-2024-57727: SimpleHelp Path Traversal Vulnerability

CVE-2024-57727 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2025-02-13

Technologies: SimpleHelp. Vendors: Simplehelp.

Executive brief

SimpleHelp remote support software is vulnerable to multiple path traversal vulnerabilities allowing unauthenticated remote attackers to download arbitrary files. Attackers can access sensitive data including server configuration files, secrets, and hashed user passwords via crafted HTTP requests.

Affected products

  • SimpleHelp SimpleHelp remote support software v5.5.7 and before

Timeline

  • 2025-01-15: disclosed: NVD Published Date
  • 2025-02-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-02-13: exploited: Reported as exploited in the wild

Related threats