ZeroHour

CVE-2024-57728

KEV ransomwaremoderate1

Zip-Slip Path Traversal RCE in SimpleHelp Remote Support 5.5.7 and Earlier

CISA: SimpleHelp Path Traversal Vulnerability

CVSS 3.1
7.2 high
EPSS
7%p94
Published
()
KEV added
AI analysis

SimpleHelp remote support software version 5.5.7 and earlier contains a path traversal flaw (zip slip, CWE-22/CWE-59) in its file upload feature, which fails to properly validate file paths inside uploaded ZIP archives. An authenticated admin user can upload a crafted ZIP file whose archive entries use traversal paths, causing files to be written anywhere on the SimpleHelp server's file system outside the intended upload directory. By placing files at attacker-chosen locations on the host, the attacker achieves arbitrary code execution in the context of the SimpleHelp server user account. Any organization running an affected SimpleHelp server is exposed, with MSPs at particular risk because the product is used as RMM software — attackers (including ransomware groups such as DragonForce and Storm-1175 operators) have chained SimpleHelp flaws to compromise an MSP and push ransomware to its downstream customers. The flaw is confirmed exploited in the wild: CISA added it to the KEV catalog on 2026-04-24 with known ransomware use, EPSS puts 30-day exploitation probability at 7% (94th percentile), and no public proof-of-concept is known.

What to do: Upgrade SimpleHelp to a release later than 5.5.7 per vendor instructions; federal agencies under BOD 22-01 must apply vendor mitigations, follow cloud-service guidance, or discontinue use of the product if mitigations are unavailable. Given known ransomware abuse via chained SimpleHelp flaws, MSPs and other operators should check SimpleHelp server logs for unexpected admin uploads and logins, look for unexpected files or services on the SimpleHelp host, and hunt for signs of lateral movement or ransomware staging on connected client machines.

Affected
SimpleHelp (remote support/RMM software)v5.5.7 and earlier (all releases up to and including 5.5.7)
Estimated exposure
moderatea few thousand internet-exposed SimpleHelp server instances (low thousands), with larger downstream exposure via MSP-managed endpoints — SimpleHelp is a niche RMM product relative to larger remote-access vendors, and public internet scans typically show only a few thousand exposed SimpleHelp servers, but each MSP deployment can manage hundreds of downstream client…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

CISA Known Exploited Vulnerability
Affected
SimpleHelp SimpleHelp
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
simple-help
Products
simplehelp
Weakness
CWE-59, CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

Storm-1175 Replaces Medusa With New StormEncryptor Ransomware

Microsoft reports China-linked ransomware group Storm-1175 switched from Medusa to a new C++ strain, StormEncryptor, likely exploiting N-able flaw CVE-2026-18577.

Microsoft Threat Intelligence reports that the financially motivated, China-linked group Storm-1175 began deploying a new ransomware strain called StormEncryptor on August 2, 2026, replacing its previous Medusa ransomware. StormEncryptor is written in C++, appends the .encrypted extension to files, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory. Microsoft assesses the group is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day. Since 2023, Storm-1175 has exploited more than 16 vulnerabilities in products including Microsoft Exchange, Ivanti, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and GoAnywhere MFT, often moving from initial access to data theft and ransomware deployment within days.

Security Affairs · Aug 13, 2026Ransomware in the wildCVE-2026-18577CVE-2026-1731CVE-2023-21529+15 CVEs