CVE-2024-57728: SimpleHelp Path Traversal Vulnerability
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
Other sources
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability identified as CVE-2024-57728?
CVE-2024-57728 is a vulnerability in SimpleHelp remote support software which allows admin users to upload arbitrary files due to a zip slip exploit, potentially executing arbitrary code in the context of the SimpleHelp server user.
What versions of SimpleHelp are affected by CVE-2024-57728?
CVE-2024-57728 affects SimpleHelp versions 5.5.7 and earlier.
What is the impact of CVE-2024-57728 on system security?
CVE-2024-57728 can allow unauthorized execution of arbitrary code which poses a significant risk to system integrity and confidentiality.
How can I remediate CVE-2024-57728 in my environment?
To remediate CVE-2024-57728, upgrade SimpleHelp to version 5.5.8 or later, which addresses the vulnerability.
Can CVE-2024-57728 be exploited remotely?
Yes, CVE-2024-57728 can be exploited remotely by an attacker with admin access to the SimpleHelp application.