Skip to content
COOEY

EXPOSURES › CVE-2024-57728

CVE-2024-57728

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-57728 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

SimpleHelp's SimpleHelp product allows admin users to execute arbitrary code via a zip-slip path traversal vulnerability.

This critical vulnerability enables remote code execution for admin users by allowing the upload of crafted zip files to arbitrary paths on the file system. DIB organizations must ensure SimpleHelp is patched immediately to prevent ransomware exploitation and unauthorized code execution on their infrastructure.

Shame score — A critical RCE vulnerability linked to ransomware that allows arbitrary file system manipulation via zip-slip exploits.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.