logo

Multiple Vulnerabilities in SimpleHelp RMM Could Allow for Arbitrary Code Execution

ID: 1ade72e3-3d77-590d-b64d-e98af53df8ad

STIX ID: report--1ade72e3-3d77-590d-b64d-e98af53df8ad

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2025-01-30

Date Updated: 2026-04-27

...
...

Multiple critical vulnerabilities in SimpleHelp RMM (CVE-2024-57727, CVE-2024-57728, CVE-2024-57726) allow unauthenticated path traversal to download sensitive files and configuration secrets, authenticated arbitrary file upload that can lead to remote code execution (or overwrite executables), and missing authorization checks that enable privilege escalation; chained exploitation can result in full server compromise and execution of arbitrary commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.