CVE-2024-57728 is a critical zip slip vulnerability affecting SimpleHelp remote support software versions 5.5.7 and earlier, allowing authenticated administrative users to upload arbitrary files anywhere on the filesystem. This flaw carries a CVSS score of 7.2 (HIGH), indicating that it can be exploited remotely with low complexity by high-privileged users, leading to complete compromise of confidentiality, integrity, and availability of the affected system. While no public exploit code is available, the vulnerability is being actively exploited in the wild by ransomware groups like DragonForce and Play, with significant community discussion and media coverage highlighting its use in MSP supply chain attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.5.8CPE matchmatch criteria | cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.