NVD disclosure day

Published threat advisories for January 15, 2025

CVE advisoryKnown Exploit

CVE-2024-57728

SimpleHelp Remote Support: Arbitrary File Upload Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in SimpleHelp remote support software allows administrative users to upload arbitrary files, potentially leading to unauthorized code execution. This could compromise affected systems, impacting business operations and data. Organizations should identify vulnerable assets, reduce exposure, and apply ven

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-57727

SimpleHelp Path Traversal Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Path traversal vulnerabilities in SimpleHelp remote support software allow unauthenticated attackers to download arbitrary files, including configuration details and user credentials. This poses a risk of data exposure and system compromise for affected organizations.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-57726

SimpleHelp: Privilege Escalation via API Keys.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in SimpleHelp remote support software allows low-privilege technicians to create API keys with excessive permissions, potentially leading to server administrator control. This could impact system integrity and data confidentiality. Organizations using affected versions should address this vulnerability.

• CISA KEV