Vulnerability threat dossier

CVE-2024-57728

simple-helpsimplehelp

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

VTP deterministic threat44.9of 100 · CVSS excluded

VTP analyst assessment

SimpleHelp authenticated zip-slip code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists this SimpleHelp vulnerability as known exploited, including known ransomware use. An administrator can upload a crafted ZIP that writes arbitrary files and executes code as the SimpleHelp server user.

Why it matters

  • Remote-support servers can provide a useful foothold into managed endpoints and support operations.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The case contains no campaign details or public exploit evidence.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use SimpleHelp 5.5.7 or earlier, apply the vendor fix promptly.

AI baseline history (2)
  1. BASELINE ASSESSED
    SimpleHelp authenticated zip-slip code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    SimpleHelp administrative zip-slip RCEgpt-5.6-sol · high
Technical severityHIGHCVSS 7.2 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityNONE KNOWNReliability not implied
EPSS0.6599th percentile · prediction
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.65; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EPSS MATERIAL INCREASEEPSS changed materially from 0.07 to 0.65
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

0publications detected
0underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

04

Event history

Threat timeline

  1. 17:4525 Sept
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.07 to 0.65

    Predictive context changed; this is not exploitation evidence.

  2. 00:0024 Apr
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

06

Technical vulnerability data

Context, not threat proof

VTP threat score44.9vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction12.93 / 20
Exploit availability0 / 15
Source independence0 / 15
Intelligence recency0 / 10
Threat acceleration2 / 10
CVSS technical severityExcluded
CVSS
7.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-22, CWE-59
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.