SimpleHelp
Vulnerabilities and patches in SimpleHelp's remote-support server — an on-prem RMM/support tool whose compromise typically hands attackers pre-authenticated technician access to every endpoint enrolled behind it. Covered here because remote-support servers are a repeat target for ransomware crews and CISA has added multiple SimpleHelp flaws to its Known Exploited Vulnerabilities catalog.
SimpleHelp OIDC Authentication Bypass
SimpleHelp 5.5.15 and prior accepts OIDC identity tokens without verifying their signature — a forged token yields a full technician session. CVSS 10.0, KEV, patch is 5.5.16.
SimpleHelp Missing Authorization Vulnerability
SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.
SimpleHelp Path Traversal Vulnerability
SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.
SimpleHelp Path Traversal Vulnerability
SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.
