PT-2025-1272 · Unknown · Simplehelp

Published

2025-01-15

·

Updated

2026-04-27

·

CVE-2024-57726

CVSS v3.1

9.9

Critical

AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SimpleHelp versions prior to 5.5.8
Description SimpleHelp remote support software contains an issue with insecure privilege management and missing authorization. This allows technicians with low privileges to create API keys with excessive permissions, which can be used to escalate privileges to the server administrator role or root level. In combination with other flaws, this enables the upload of arbitrary files to the server and the execution of remote code. These flaws have been exploited in real-world incidents by groups such as DragonForce and Play, targeting Managed Service Providers (MSPs) and their clients to facilitate data theft, supply chain compromise, and ransomware deployment. The Play ransomware group has reportedly impacted approximately 900 victims worldwide.
Recommendations Versions prior to 5.5.8: Update the software to a version released after January 2025 that contains the security patches.

Fix

RCE

Improper Privilege Management

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-00724
CVE-2024-57726

Affected Products

Simplehelp