ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Critical SimpleHelp vulnerabilities fixed, update your server instances!

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-57726
+2 in the same advisory: …57727 …57728
Missing-Authorization Privilege Escalation in SimpleHelp Remote Support <= 5.5.7

SimpleHelp remote support software versions 5.5.7 and earlier contain a missing-authorization flaw (CWE-862) that lets low-privileged technicians create API keys with excessive permissions. A network attacker holding only a technician-level account can mint such an over-privileged API key and use it to escalate to the SimpleHelp server admin role, with no user interaction required (CVSS 3.1 score 9.9, scope changed). Successful exploitation yields full administrative control of the SimpleHelp server, the remote-access/RMM platform support staff use to reach endpoints, which can also expose downstream customer environments when the server is run by an MSP. Any organization running SimpleHelp 5.5.7 or earlier is affected, with MSPs at particular risk given their downstream reach. The flaw is confirmed exploited in the wild: it was added to CISA KEV on 2026-04-24 with known ransomware use, carries a 66.6% EPSS score (99th percentile), and public reporting describes ransomware operators chaining SimpleHelp flaws in double-extortion attacks against an MSP and its customers.

Do: Upgrade SimpleHelp to the latest vendor release newer than 5.5.7 and apply vendor mitigation guidance; federal agencies must meet BOD 22-01 requirements or discontinue use. Audit existing API keys (especially those created by technician accounts) for excessive permissions, review audit logs for unexpected key creation or admin activity, and restrict internet exposure of SimpleHelp servers. Organizations whose MSP uses SimpleHelp should confirm the MSP's instance is patched before trusting remote sessions.

9.9
group max
67% KEV ransomware
  • SimpleHelp remote support software 5.5.7 and earlier
moderatelow thousands of exposed self-hosted SimpleHelp server deployments (est.), amplified to many downstream endpoints where instances are run by MSPs
Full article434 words · extracted from helpnetsecurity.com · click to collapse

If you’re an organization using SimpleHelp for your remote IT support/access needs, you should update or patch your server installation without delay, to fix security vulnerabilities that may be exploited by remote attackers to execute code on the underlying host.

SimpleHelp remote support vulnerabilities

The vulnerabilities

SimpleHelp is relatively popular remote support/access software that has also occasionally been used by cyber attackers.

The solution is mostly used by technical services firms and organizations’ IT help desk and technical support teams. It uses the Java runtime environment to run its server and client components and, thus, can be run on Windows, macOS or Linux machines.

Horizon3.ai researchers have recently probed the software for security weaknesses, and have discovered three vulnerabilities:

  • CVE-2024-57727, an unauthenticated path traversal vulnerability that could allow attackers to download arbitrary files from the SimpleHelp server, including logs and configuration secrets (encrypted with a hardcoded key)
  • CVE-2024-57728, an arbitrary file upload flaw that could be exploited by authenticated attackers (e.g., leveraging admin credentials gleaned from downloading config files) to upload arbitrary files to the machine running the SimpleHelp server or even interact with/access remote machines if the “unattended access” option is switched on. “For Linux servers, an attacker could exploit this vulnerability to upload a crontab file to execute remote commands. For Windows servers, an attacker could overwrite executables or libraries used by SimpleHelp to get to remote code execution,” the researchers explained.
  • CVE-2024-57726, a vulnerability stemming from missing authorization checks for certain admin function could be misused by attackers to elevate their privileges to admin and, for example, exploit CVE-2024-57728 to take over the server.

A Shodan search has revealed nearly 3,500 internet-facing SimpleHelp servers, the researchers noted, but how many are still unpatched is unknown.

SimpleHelp remote support vulnerabilities

Internet-facing SimpleHelp servers (Source: Horizon3.ai)

Update or patch, and change passwords

The researchers refrained from publishing additional technical details for now, but they say that the flaws are trivial to reverse and exploit, and users should upgrade to a fixed version (5.5.8) or apply a patch to v5.4.10 or 5.3.9 as soon as possible.

“While we do not know of any exploits of this vulnerability, it is possible that the server’s configuration file could be exposed,” the company developing the software said.

With that in mind, they also advised organizations to:

  • Change the Administrator password of the SimpleHelp server
  • Change the passwords for Technician accounts (where possible), and
  • Restrict the IP addresses that the SimpleHelp server can expect Technician and Administrator logins from (where possible).

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/01/16/critical-simplehelp-vulnerabilities-fixed-security-update-remote-support/