Unauthenticated Path Traversal File Download in SimpleHelp 5.5.7 and Earlier
CISA: SimpleHelp Path Traversal Vulnerability
CVSS 3.1
7.5high
EPSS
95%p100
Published
()
KEV added
AI analysis
CVE-2024-57727 consists of multiple path traversal vulnerabilities (CWE-22) in SimpleHelp remote support/remote access software that affect versions 5.5.7 and earlier. Because affected request handlers do not properly validate file paths, an unauthenticated remote attacker can send crafted HTTP requests to traverse directories and download arbitrary files from the SimpleHelp server host. The attacker gains access to sensitive server configuration files containing secrets and hashed user passwords, which can support follow-on attacks such as offline password cracking and deeper compromise; ransomware operators have chained SimpleHelp flaws in double-extortion attacks, including against an MSP and its downstream customers. Any organization running SimpleHelp is affected, particularly internet-facing deployments and MSPs that use the product for remote support and access. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2025-02-13 with known ransomware use, EPSS assigns a 95.2% probability of exploitation within 30 days, and reporting links exploitation to campaigns such as a DragonForce operator targeting an MSP and its customers and Storm-1175 ransomware activity.
What to do: Upgrade all SimpleHelp servers to a patched release newer than 5.5.7 per the vendor's instructions, or apply vendor-recommended mitigations or discontinue use if patching is unavailable (the CISA KEV required action). Since the flaw exposes configuration files and hashed user passwords, rotate embedded secrets and force credential/password resets, and review SimpleHost/server access logs for unauthenticated traversal-style download requests. MSPs should check their SimpleHelp server for signs of compromise, as ransomware operators have chained these flaws to reach downstream customers.
moderate≈1,000–2,000 internet-exposed SimpleHelp servers — Public internet-wide scans around the time of disclosure identified on the order of 1,000–2,000 SimpleHelp servers exposed to the internet, and because many are operated by MSPs serving downstream clients, the number of impacted…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.
CISA Known Exploited Vulnerability
Affected
SimpleHelp SimpleHelp
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Microsoft reports China-linked ransomware group Storm-1175 switched from Medusa to a new C++ strain, StormEncryptor, likely exploiting N-able flaw CVE-2026-18577.
Microsoft Threat Intelligence reports that the financially motivated, China-linked group Storm-1175 began deploying a new ransomware strain called StormEncryptor on August 2, 2026, replacing its previous Medusa ransomware. StormEncryptor is written in C++, appends the .encrypted extension to files, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory. Microsoft assesses the group is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day. Since 2023, Storm-1175 has exploited more than 16 vulnerabilities in products including Microsoft Exchange, Ivanti, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and GoAnywhere MFT, often moving from initial access to data theft and ransomware deployment within days.