CVE-2024-57728
HIGH(7.2)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CVSS 7.2 — Hoch
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
7.0%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.2
Technische Schwere
SecBoard-Einordnung
CVE-2024-57728 betrifft die Remote-Support-Software SimpleHelp in Version 5.5.7 und früher. Die Schwachstelle ist ein Zip-Slip-Problem, das es administrativen Benutzern ermöglicht, beliebige Dateien an beliebigen Stellen im Dateisystem hochzuladen. Dies kann zur Ausführung von beliebigem Code auf dem Host im Kontext des SimpleHelp-Server-Benutzers führen.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
Referenzen
- https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabi...
- https://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-...
- https://www.microsoft.com/en-us/security/blog/2026/04/06/storm-1175-focuses-gaze...
- https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomwar...