First published: Wed Jan 15 2025(Updated: )
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SimpleHelp | <5.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-57726 is a high-severity vulnerability that allows unauthorized API key creation, enabling privilege escalation.
To fix CVE-2024-57726, upgrade SimpleHelp to version 5.5.8 or later to eliminate the excessive permissions for API keys.
CVE-2024-57726 affects all versions of SimpleHelp remote support software up to and including v5.5.7.
Attackers can exploit CVE-2024-57726 to create API keys that grant them unauthorized access and potentially elevate their privileges to server admin.
SimpleHelp is remote support software, and CVE-2024-57726 identifies a security flaw in it that allows for privilege escalation through API keys.