CVE-2024-57727
SimpleHelp: Path Traversal
As of , CVE-2024-57727 in SimpleHelp is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 13 February 2025
- US federal deadline
- 6 March 202521 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- KnownCISA changed it from Unknown to Known on 9 June 2025.
- EPSS score
- 0.97Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- Public exploit
- 1 Metasploit module
- Fix
- Vendor advice: simple-help.comLinks below, from CISA's entry.
What CISA says to do
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
CISA's required action
What the flaw is
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.
CISA's description
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
The CVE record's description, from mitre
- CVE published
- 15 January 2025
- Assigned by
- mitre
- CVSS
- 9.1 Critical (CVSS 3.1, from CISA-ADP)
- CWE-22
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- total
Timeline
- The CVE record was published.
- CISA added it to its list of exploited vulnerabilities.
- CISA changed its entry. Edited: notes.
- The US federal deadline to fix it.
- CISA changed its entry. Ransomware use: Unknown to Known.
- CISA changed its entry. Edited: notes.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: SimpleHelp Path Traversal Vulnerability CVE-2024-57727auxiliary module, rank normal
SimpleHelp: other exploited entries
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2024-57726Missing Authorization | SimpleHelp SimpleHelp | Patch nowRansomware use, listed within a year | 0.67 | ||
| CVE-2024-57728Path Traversal | SimpleHelp SimpleHelp | Patch nowRansomware use, listed within a year | 0.65 | ||
| CVE-2026-48558Authentication Bypass | SimpleHelp SimpleHelp | Patch this weekMetasploit module | 0.06 |
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org