PT-2025-1273 · Unknown · Simplehelp
Published
2025-01-15
·
Updated
2026-06-15
·
CVE-2024-57727
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SimpleHelp versions 5.5.7 and earlier
Description
SimpleHelp remote support software is affected by multiple path traversal vulnerabilities. These flaws allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. The downloaded files may include server configuration files containing sensitive information, such as secrets and hashed user passwords. This vulnerability is actively exploited by ransomware actors, including the DragonForce and Play ransomware groups, in double-extortion attacks. Approximately 580 vulnerable instances have been identified. Exploitation has been observed targeting utility billing providers and managed service providers (MSPs). The vulnerability allows attackers to steal credentials, escalate privileges, and deploy ransomware.
Recommendations
Update SimpleHelp to a version later than 5.5.7.
Fix
RCE
LPE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simplehelp