Multiple Vulnerabilities in SimpleHelp RMM Could Allow for Arbitrary Code Execution
ID: 1ade72e3-3d77-590d-b64d-e98af53df8ad
STIX ID: report--1ade72e3-3d77-590d-b64d-e98af53df8ad
Feed Name: CISecurity.org Advisories
Threat Score
Multiple critical vulnerabilities in SimpleHelp RMM (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726) allow unauthenticated path traversal to download sensitive files and configuration secrets, authenticated arbitrary file upload that can lead to remote code execution (or overwrite executables), and missing authorization checks that enable privilege escalation; chained exploitation can result in full server compromise and execution of arbitrary commands.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
