SimpleHelp Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Vulnerability

A vulnerability allowing arbitrary code execution has been identified in SimpleHelp versions prior to 5.5.12. This issue arises from the inclusion of functionality from an untrusted control sphere, which can be exploited to induce a client to execute unauthorized code.

Impact

Exploitation of this vulnerability allows for complete compromise of remote machines, enabling an unauthenticated attacker to execute arbitrary code on the affected system.

Remediation

Users are advised to upgrade to SimpleHelp version 5.5.12 or later.

Added: Jul 25, 2025, 8:35 PM
Updated: Jul 25, 2025, 8:35 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
10.0
exploitability
6.5
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.