CRITICAL

CVE-2024-57726

Simple-help Simplehelp 2025-01-15 CVSS v3.1
CVSS
9.9
KEV

Description

SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

Summary dbcve.org

SimpleHelp v5.5.7 and prior contains a privilege escalation vulnerability where low-privilege technicians can create API keys with excessive permissions beyond their assigned role. These over-privileged API keys can then be used to perform actions reserved for server administrators, effectively allowing lateral movement to full administrative control of the SimpleHelp server.

Mitigation

Apply vendor-provided patch for SimpleHelp v5.5.7 or later; immediately audit existing API keys for excessive permissions and revoke any unauthorized admin-level keys; consider restricting API key creation permissions until patch is applied.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

66.6%
Probability of exploitation in next 30 days
99.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE