SimpleHelp released fixes for three critical vulnerabilities in its remote support and RMM software that can be chained to gain full control of vulnerable servers. The flaws are tracked as CVE-2024-57726, an authorization weakness that allows privilege escalation to administrator; CVE-2024-57727, an unauthenticated arbitrary file download issue that can expose sensitive data and credentials; and CVE-2024-57728, an authenticated administrator file upload flaw that can lead to remote code execution. Horizon3.ai disclosed the issues, and affected versions include SimpleHelp 5.5 before 5.5.8, 5.4 before 5.4.10, and 5.3 before 5.3.9.
CSIRT.SK reported that attackers have already targeted exposed SimpleHelp RMM systems, with Arctic Wolf observing intrusions in which threat actors used leaked credentials or exploited the vulnerabilities for initial access and compromise. The vendor urged organizations to patch immediately, rotate administrator and technician passwords, and restrict those account logins to trusted IP addresses to reduce the risk of server takeover and downstream compromise of managed endpoints.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
An update dated 2025-01-30 reported that Arctic Wolf had observed attacks against SimpleHelp RMM systems. According to the report, attackers used leaked credentials or exploited the three SimpleHelp CVEs for initial access and compromise.
SimpleHelp released security updates addressing three critical flaws in its remote access and RMM software: CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728. The affected versions were 5.5 before 5.5.8, 5.4 before 5.4.10, and 5.3 before 5.3.9.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecsirt.sk
Open sourcehorizon3.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.