>> All posts

CVE-2024-57726 (with CVE-2024-57728): SimpleHelp privilege escalation to remote code execution

The short version: SimpleHelp remote-support software (v5.5.7 and earlier) has a missing-authorization flaw (CVE-2024-57726) that lets a low-privilege technician account escalate to administrator, and a companion "zip slip" file-upload flaw (CVE-2024-57728) that turns admin access into code execution on the host. Paired with the unauthenticated file-read flaw in the same batch (CVE-2024-57727), they form a full path from outsider to server takeover — and they've been used in real intrusions, including ransomware. Both are in CISA's KEV catalog. Steady hands — but move: upgrade to 5.5.8.

At a glance

FactDetail
Our severity takeCritical — a chain from low-privilege (or unauthenticated) to code execution, exploited in the wild
CVSS v3.1 (NVD) — CVE-2024-577269.9 — Critical · AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (CWE-862 missing authorization)
CVSS v3.1 (NVD) — CVE-2024-577287.2 — High · AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H (CWE-59 / CWE-22, zip-slip file upload → RCE)
EPSS9.33% · 95th percentile (2026-07-17, CVE-2024-57726)
In CISA KEV?Yes — both — remediation due 2026-05-08 (added 2026-04-24)
Known exploited?Yes — tied to real intrusions, including ransomware
Requires authenticated session?CVE-2024-57726 needs a low-privilege account; combined with CVE-2024-57727 the chain starts unauthenticated
AffectedSimpleHelp 5.5.7 and earlier
Fixed in5.5.8

What you need to know

SimpleHelp is a remote-support tool — the kind of software that, by design, has deep reach onto the machines it supports. In early 2025, Horizon3.ai disclosed a set of flaws in it that combine cleanly:

  • CVE-2024-57727 (the way in) — an unauthenticated path traversal that lets an attacker download server files, including serverconfig.xml with secrets and hashed credentials.
  • CVE-2024-57726 (the lift) — a missing-authorization flaw: a low-privilege technician account can call backend functions it shouldn't, escalating to administrator. On its own it's rated 9.9.
  • CVE-2024-57728 (the payoff) — a zip-slip file upload available to admins that writes files anywhere on the filesystem, yielding code execution as the SimpleHelp server user.

Read together, an outsider harvests credentials, escalates to admin, and executes code — server takeover. Attackers, including ransomware operators, adopted the chain, which is why these entries carry a KEV deadline.

How serious we see it

Critical — as a chain, and by real-world use.

Each piece is serious; combined, they take an attacker from unauthenticated to full control of a remote-support server that reaches your endpoints. That's exactly the profile that goes to the top of the queue, reinforced by KEV listing and in-the-wild exploitation. The bounded, reassuring part is that a single upgrade closes the whole batch: SimpleHelp fixed these in 5.5.8, the affected range is clear, and exposure is quick to confirm. As always with exploited-before-you-patched flaws, patched and clean are separate questions.

Recommendations

Straight from the vendor's bulletin and CISA:

  1. Patch now. Upgrade SimpleHelp to 5.5.8 or later — this addresses CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728 together.
  2. Rotate secrets. Because CVE-2024-57727 exposes serverconfig.xml (secrets, hashed passwords), reset admin/technician credentials and any secrets stored on the server after upgrading.
  3. Get the server off the open internet. Restrict SimpleHelp access to trusted networks or a VPN.
  4. Hunt for prior use. Given active exploitation, review the host for new accounts, unexpected files/uploads, web shells, and anomalous technician activity; investigate downstream endpoints.
  5. Confirm your exposure first. Verify whether any SimpleHelp server is internet-facing and which version it runs.

How BreachRisk sees it

BreachRisk discovers internet-facing SimpleHelp servers from little more than your domain, fingerprints the version, and flags exposure tied to these KEV-listed, actively exploited flaws — raised to the top of your results because they're in KEV. We detect and flag the exposed, affected server; we don't escalate privileges or upload files to prove the chain.

That outside-in, continuous view is the point for remote-support software: it reaches your endpoints, so an exposed, out-of-date SimpleHelp is one of the assets you most want mapped and prioritized before someone else strings the chain together.

References

See your cyber risk, proven.