CVE-2024-57728
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
CISA KEV
- Vendor
- SimpleHelp
- Product
- SimpleHelp
- Due date
- 2026-05-08
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier ; https://nvd.nist.gov/vuln/detail/CVE-2024-57728
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.