PT-2025-1272 · Unknown · Simplehelp

Published

2025-01-15

·

Updated

2026-05-25

·

CVE-2024-57726

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SimpleHelp remote support software versions 5.5.7 and before
Description The issue allows low-privileges technicians to create API keys with excessive permissions, which can be used to escalate privileges to the server admin role. Attackers can also upload arbitrary files to the SimpleHelp server and escalate privileges, allowing remote code execution (RCE) to be carried out. Hackers are exploiting these flaws for ransomware preparation, gaining access, persistence, and lateral movement.
Recommendations SimpleHelp remote support software versions 5.5.7 and before: Update to a version that includes a fix for this issue to prevent low-privileges technicians from creating API keys with excessive permissions and to mitigate the risk of ransomware exploits. As a temporary workaround, consider restricting the creation of API keys and limiting privileges for technicians to minimize the risk of exploitation.

Fix

RCE

Missing Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2025-00724
CVE-2024-57726

Affected Products

Simplehelp