CVE-2024-57728 Details
Description
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
A vulnerability in SimpleHelp remote support software in versions through 5.5.7 allows admin users to upload arbitrary files to any location on the file system. This is achieved by exploiting a crafted zip file, a technique known as zip slip. The vulnerability can be used to execute arbitrary code on the host, with the execution occurring in the context of the SimpleHelp server user.
Users are advised to upgrade to SimpleHelp version 5.5.8 or later. For those using SimpleHelp v5.4, a patch for version 5.4.10 is available. Users on v5.3 can upgrade to version 5.3.9. Additional steps include changing the administrator password, updating technician account passwords, and restricting IP addresses for logins.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| SimpleHelp Path Traversal Vulnerability | Apr 24, 2026 | May 8, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| simple-help simplehelp | < 5.5.8 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | Modified Analysis | [email protected] |
| Apr 24, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Apr 24, 2026 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | CVE Modified | CISA-ADP |
| Jan 16, 2025 | Initial Analysis | [email protected] |
| Jan 15, 2025 | New CVE Received | [email protected] |