🛡 CVE-2024-57727
SimpleHelp Path Traversal Vulnerability
SimpleHelp SimpleHelp CWE-22
Ransomware use
KNOWN
CISA KEV
EPSS
95.2%
Likely exploited · 100th pct
Added to KEV
2025-02-13
CISA
Remediate by
2025-03-06
⚠ OVERDUE
CWE
CWE-22
weakness
📈 EPSS exploit probability
95.2%
FIRST EPSS — 30-day probability of exploitation in the wild · band Likely exploited · higher than 100% of all scored CVEs
⚠ KEV remediation overdue
CISA required federal remediation by 2025-03-06. This exploited vulnerability is past its Binding Operational Directive 22-01 due date — prioritize patch/mitigation and hunt for exploitation.
📄 Description
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server c
🏹 Attributed exploitation
Malware / ransomware (KEV): ransomware (KEV-flagged)
🔗 External references & OSINT
🔄 Internal pivots & actions
🛡 Add to case
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron