Status: KEV
| Advisory ID: CVE-2024-57728
Key Details
| CVE | CVE-2024-57728 |
| Vulnerability Name | SimpleHelp Path Traversal Vulnerability |
| Affected products | SimpleHelp SimpleHelp |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-04-24. |
| Exploitation prediction (EPSS) | 64.66% probability of exploitation in the next 30 days (99% percentile) -- FIRST.org's EPSS model. |
| Federal remediation deadline | 2026-05-08 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
What to Do
Monitor SimpleHelp 's web page for any future patch releases.
References
KEV Required Action