Vulnerability threat dossier
CVE-2024-57728
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
VTP analyst assessment
SimpleHelp authenticated zip-slip code execution
Assessment
CISA KEV lists this SimpleHelp vulnerability as known exploited, including known ransomware use. An administrator can upload a crafted ZIP that writes arbitrary files and executes code as the SimpleHelp server user.
Why it matters
- Remote-support servers can provide a useful foothold into managed endpoints and support operations.
Evidence
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
The case contains no campaign details or public exploit evidence.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Next watchpoint
If you use SimpleHelp 5.5.7 or earlier, apply the vendor fix promptly.
AI baseline history (2)
- BASELINE ASSESSEDSimpleHelp authenticated zip-slip code executiongpt-5.6-terra · low
- BASELINE ASSESSEDSimpleHelp administrative zip-slip RCEgpt-5.6-sol · high
VTP deterministic assessment
Why this matters
- 01
CISA KEV lists this vulnerability as known to be exploited globally.
- 02
EPSS is 0.65; this is predictive context, not exploitation evidence.
- 03
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Material change ledger
What changed
Claim provenance
Evidence and source independence
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Event history
Threat timeline
- 17:4525 SeptEPSS MATERIAL INCREASE
EPSS changed materially from 0.07 to 0.65
Predictive context changed; this is not exploitation evidence.
- 00:0024 AprKEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
Original publications
Source record
Technical vulnerability data
Context, not threat proof
- CVSS
- 7.2 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-22, CWE-59
- CPE records
- 1
- Deterministic history records
- 20
Raw observations
First-party sensor records
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.