CVE-2024-57728
HIGH KEV RANSOMWARESimple-help Simplehelp < 5.5.8 - Symlink Following
Title source: ruleDescription
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
References (5)
Scores
CVSS v3
7.2
EPSS
0.0117
EPSS Percentile
78.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2026-04-24
VulnCheck KEV
2025-04-17
Ransomware Use
Confirmed
CWE
CWE-22
CWE-59
Status
published
Products (1)
simple-help/simplehelp
< 5.5.8
Published
Jan 15, 2025
KEV Added
Apr 24, 2026
Tracked Since
Feb 18, 2026