SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
History

Fri, 31 Jan 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Simple-help
Simple-help simplehelp
Weaknesses CWE-59
CPEs cpe:2.3:a:simple-help:simplehelp:*:*:*:*:*:*:*:*
Vendors & Products Simple-help
Simple-help simplehelp
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Wed, 15 Jan 2025 23:00:00 +0000

Type Values Removed Values Added
Description SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-01-15T00:00:00.000Z

Updated: 2025-01-31T20:21:30.977Z

Reserved: 2025-01-09T00:00:00.000Z

Link: CVE-2024-57728

cve-icon Vulnrichment

Updated: 2025-01-16T14:56:58.070Z

cve-icon NVD

Status : Modified

Published: 2025-01-15T23:15:09.777

Modified: 2025-01-31T21:15:12.330

Link: CVE-2024-57728

cve-icon Redhat

No data.