Executive brief
SimpleHelp remote support software is vulnerable to multiple path traversal vulnerabilities allowing unauthenticated remote attackers to download arbitrary files. Attackers can access sensitive data including server configuration files, secrets, and hashed user passwords via crafted HTTP requests.
Affected products
- SimpleHelp SimpleHelp remote support software v5.5.7 and before
Timeline
- 2025-01-15: disclosed: NVD Published Date
- 2025-02-13: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-02-13: exploited: Reported as exploited in the wild