CVE-2024-57728
9.5 CISA KEVSimpleHelp · SimpleHelp
A zip slip path traversal vulnerability in SimpleHelp remote support software allows authenticated administrators to upload arbitrary files, leading to remote code execution.
Executive summary
A critical path traversal vulnerability in SimpleHelp allows for arbitrary code execution and is currently being exploited in the wild, potentially facilitating ransomware attacks.
Vulnerability
The vulnerability is a zip slip flaw that enables an authenticated administrator to upload a crafted zip file containing malicious payloads to arbitrary locations on the file system. This allows for code execution under the context of the SimpleHelp server user.
Business impact
The ability for an attacker to achieve remote code execution on a remote support server is catastrophic, as these servers often have persistent, high-level access to the entirety of an organization's managed endpoints. A compromise of the SimpleHelp server can lead to widespread malware deployment, including ransomware, across the entire enterprise network.
Remediation
Immediate Action: Update SimpleHelp to version 5.5.8 or later immediately. Patches are also available for older branches, specifically v5.4.10 and v5.3.9.
Proactive Monitoring: Monitor logs for administrative actions involving file uploads or unusual processes spawned by the SimpleHelp server application.
Compensating Controls: Restrict administrative access to the SimpleHelp console to a strictly limited set of IP addresses and require multi-factor authentication for all administrative sessions.
Exploitation status
Public Exploit Available: Unknown (No confirmed weaponized exploit or public PoC in the provided data).
Analyst recommendation
Given the active exploitation and the potential for full-scale network compromise via this remote support software, immediate patching is mandatory. Organizations should treat this as a critical incident and verify that all SimpleHelp instances are updated to the secure versions provided by the vendor.