Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

CSRF in SimpleHelp customer installer hostname parameter

IdentifiersCVE-2025-36728CWE-352· Cross-Site Request Forgery (CSRF)

CVE-2025-36728 is a cross-site request forgery issue in SimpleHelp before version 5.5.11 affecting the customer download/installer workflow. The vulnerable design allows the installer download URL to carry a hostname parameter that influences where the client retrieves additional installation resources. An attacker can craft a malicious SimpleHelp download link with this parameter set to an attacker-controlled server. When the victim follows the link and launches the installer, the client fetches installation resources from the attacker-specified host instead of the legitimate SimpleHelp server. On its own, this issue redirects trust in the installation flow; in the reported attack chain it is used to steer the client to untrusted content, enabling follow-on exploitation with CVE-2025-36727, where attacker-supplied binaries/functionality can be downloaded and executed.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

The primary impact of CVE-2025-36728 is that it lets an attacker influence the source of installation resources used by the SimpleHelp client/installer. This breaks the expected trust boundary between the SimpleHelp server and the customer installer. In practice, the issue is most serious when chained with CVE-2025-36727: the attacker can cause the victim to retrieve resources from attacker infrastructure and then execute attacker-controlled content, resulting in remote code execution on the victim system from a single malicious URL click. Even without the second issue, CVE-2025-36728 enables redirection of installer behavior to attacker infrastructure and exposure to malicious update/install content.

Mitigation

If you can’t patch tonight, do this now.

Until patching is complete, only distribute SimpleHelp installers and support links through trusted, authenticated channels and instruct users not to launch support tools from unsolicited links. Restrict use of remote monitoring and management tools to an approved inventory, block unauthorized RMM installations, and audit RMM session activity and logs for abnormal behavior. Monitor network traffic for suspicious SimpleHelp installer downloads, unexpected outbound connections during installation, and connections to non-approved hosts serving SimpleHelp resources. Scan for known RMM-related listening services and investigate unusual support-tool activity. Where possible, use network controls to limit installer/resource retrieval to approved SimpleHelp servers only.

Remediation

Patch, then assume compromise.

Upgrade SimpleHelp to version 5.5.11 or later, as the issue affects versions before 5.5.11 and the vendor reportedly fixed the vulnerabilities. Replace any exposed or distributed customer download links that may still reference vulnerable installer workflows. Validate that installer/resource retrieval is constrained to trusted SimpleHelp infrastructure and that any legacy deployment artifacts, cached installers, or self-hosted download pages are updated. Review vendor guidance and apply all related fixes for the associated trust/validation issue CVE-2025-36727 as well, because the practical risk described in the source material depends on chaining both flaws.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
SimpleHelpSimplehelpapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.