Safeguard
Vulnerability Analysis

SimpleHelp's Two Confirmed-Exploited Bugs Form a Complete Ransomware Attack Chain

A missing authorization flaw and a path traversal RCE in SimpleHelp remote support software, both confirmed for Medusa and DragonForce ransomware operations.

Safeguard Research Team
4 min read

SimpleHelp, remote support software used by IT teams and managed service providers to reach and control end-user machines, had two vulnerabilities confirmed exploited and both flagged by CISA for known ransomware campaign use — a missing authorization bug that turns a low-privilege technician account into full server admin, and a path traversal flaw that turns that admin access into arbitrary code execution on the host.

CVECVSSFlawRansomware Use
CVE-2024-577269.9Missing authorizationKnown
CVE-2024-577287.2Path traversal (zip slip)Known

Why these two bugs describe a complete attack chain, not two independent findings

CVE-2024-57726 lets a low-privileged technician account — the kind of restricted role a support organization hands out to junior staff or subcontracted help desk personnel specifically because it isn't supposed to carry admin-level trust — create API keys with excessive permissions, and use those keys to escalate straight to the server admin role. That alone is a serious authorization failure. But CVE-2024-57728 is where it becomes something far more damaging: with admin access in hand, an attacker can upload a crafted zip file exploiting classic zip-slip path traversal to write arbitrary files anywhere on the file system, which is directly leveraged to execute arbitrary code in the context of the SimpleHelp server user. Read together, the two CVEs form a single practical chain — start with any technician-level credential, however limited, escalate to admin through the authorization bug, then use that admin access to achieve full remote code execution through the path traversal bug. Both vulnerabilities affect the same version range, v5.5.7 and earlier, meaning any unpatched SimpleHelp deployment is exposed to the entire chain simultaneously, not just one link of it.

Why remote support software is a uniquely attractive ransomware entry point

CISA's references for both CVEs point to Microsoft's documentation of Storm-1175 using this exact vulnerability pair in "high-tempo Medusa ransomware operations," and to Trend Micro's ransomware spotlight coverage of DragonForce — meaning this isn't a single opportunistic incident but a vulnerability chain multiple distinct ransomware operations have folded into their standard playbook. The reason remote support tools make such efficient ransomware entry points is structural: a SimpleHelp server, by design, holds standing remote-access relationships to potentially every endpoint an MSP or IT department manages, which means compromising the SimpleHelp server itself — rather than any single endpoint — hands an attacker the same fleet-wide reach the legitimate support staff have, in one step. For a managed service provider specifically, this converts a single vulnerable SimpleHelp instance into simultaneous initial access across every downstream customer environment that provider services, which is precisely the "one compromise, many victims" leverage ransomware affiliates look for.

What to check this week

  • Patch SimpleHelp to a version beyond 5.5.7 immediately if not already done, treating this as a live, ransomware-confirmed exposure rather than a routine update given both vulnerabilities' documented use by Storm-1175 and DragonForce-linked actors.
  • Audit all existing API keys for scope creep, since the authorization bug's specific mechanism was technician accounts minting keys with permissions beyond their assigned role — any key with admin-equivalent scope tied to a non-admin account is a red flag regardless of when it was created.
  • Review SimpleHelp server logs for zip file uploads and any file writes landing outside expected content directories, the specific fingerprint of the path traversal exploitation chain.
  • If your organization is a downstream customer of an MSP, ask directly whether the provider's SimpleHelp instance — or equivalent remote support tooling — has been patched, since the fleet-wide reach that makes this vulnerability valuable to ransomware actors runs through the provider, not through your own environment.

A closing note on the technician-to-admin trust gap

Support organizations routinely grant technician-level accounts specifically because full admin access isn't supposed to be necessary for day-to-day ticket work — a deliberate least-privilege design choice that CVE-2024-57726 undermines entirely by making that boundary trivially crossable. Any organization relying on role separation within a remote support platform as a compensating control should treat this cluster as evidence that the control itself needs to be verified against the current patched version, not assumed to be structurally sound.

How Safeguard helps

Safeguard's continuous inventory flags remote support and remote management software with the elevated scrutiny that its fleet-wide reach warrants, recognizing that a vulnerability chain confirmed for use by multiple ransomware operations against exactly this category of tooling represents outsized risk relative to a typical single-endpoint finding.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.