• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploiting-flaws-in-simplehelp-rmm-to-breach-networks/

Hackers exploiting flaws in SimpleHelp RMM to breach networks

BleepingComputer
·
Bill Toulas
·
Published Jan 28, 2025
·
Updated

Hackers are believed to be exploiting recently fixed SimpleHelp Remote Monitoring and Management (RMM) software vulnerabilities to gain initial access to target networks. The flaws, tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, allow threat actors to download and upload files on devices and escalate privileges to administrative levels. The vulnerabilities were discovered and disclosed by Horizon3 researchers two weeks ago. SimpleHelp released fixes between January 8 and 13 in product versions 5.5.8, 5.4.10, and 5.3.9. Arctic Wolf now reports about an ongoing campaign targeting SimpleHelp servers that started roughly a week after Horizon3's public disclosure of the flaws. The security company isn't 100% certain that the attacks leverage these flaws but connects its observations to Horizon3's report with medium confidence. "While it is not confirmed that the recently disclosed vulnerabilities are responsible for the observed campaign, Arctic Wolf strongly recommends upgrading to the latest available fixed versions of the SimpleHelp server software where possible," reads the report. "In situations where the SimpleHelp client was previously installed on devices for third-party support sessions but isn't actively being used for day-to-day operations, Arctic Wolf recommends uninstalling the software to reduce the potential attack surface." Threat monitoring platform Shadowserver Foundation reported they see 580 vulnerable instances exposed online, most (345) locat...

Read full article

Affected Software

6 affected components
SimpleHelp Remote Monitoring and Management=5.5.8
SimpleHelp Remote Monitoring and Management=5.4.10
SimpleHelp Remote Monitoring and Management=5.3.9
SimpleHelp Remote Monitoring and Management=5.5.8
SimpleHelp Remote Monitoring and Management=5.4.10
SimpleHelp Remote Monitoring and Management=5.3.9
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are being exploited by hackers in the SimpleHelp RMM?

Hackers are exploiting the vulnerabilities tracked as CVE-2024-57726 and CVE-2024-57727.

2

What is the primary function of the SimpleHelp Remote Monitoring and Management software?

SimpleHelp RMM is designed for remote monitoring and management of network and system performance.

3

Which versions of SimpleHelp RMM are affected by the reported vulnerabilities?

Versions 5.3.9, 5.4.10, and 5.5.8 of SimpleHelp RMM are affected by the vulnerabilities.

4

What actions should users take to mitigate the security risks associated with these vulnerabilities?

Users should update their SimpleHelp RMM software to the latest version to mitigate security risks.

5

What are the potential consequences of exploiting these SimpleHelp RMM vulnerabilities?

Exploitation of these vulnerabilities could allow unauthorized access to target networks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203