---
id: CVE-2024-57727
title: >-
  SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple
  path traversal vulnerabilities that enable unauthenticated remote attackers to
  download arbitrary files from the SimpleHelp host via crafted HTTP requests
summary: >-
  SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple
  path traversal vulnerabilities that enable unauthenticated remote attackers to
  download arbitrary files from the SimpleHelp host via crafted HTTP requests.
  Th…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
  - CWE-22
vendor: simple-help
product: simplehelp
affected:
  - simplehelp < 5.5.8
patched:
  - simplehelp 5.5.8
published: '2025-01-15'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-57727'
references:
  - url: >-
      https://simple-help.com/kb---security-vulnerabilities-01-2025#security-vulnerabilities-in-simplehelp-5-5-7-and-earlier
    label: cve@mitre.org
  - url: >-
      https://www.horizon3.ai/attack-research/disclosures/critical-vulnerabilities-in-simplehelp-remote-support-software/
    label: cve@mitre.org
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-57727
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.95151
epssPercentile: 0.99863
kev: true
kevDateAdded: '2025-02-13'
kevDueDate: '2025-03-06'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-04T05:36:12.842Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/imjdl/CVE-2024-57727'
  metasploit:
    - auxiliary/scanner/http/simplehelp_toolbox_path_traversal
  nuclei:
    - CVE-2024-57727
  checkedAt: '2026-09-21T15:27:03.614Z'
exploitAvailable: true
---

## Overview

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords.

## Affected

- `simplehelp < 5.5.8`

## Remediation

Upgrade past the affected range:

- `simplehelp 5.5.8`
