Bypass Bug Revives Critical N-Day in Mitel MiCollab
ID: 415cbacc-974b-5228-8dfc-7c2c054006aa
STIX ID: report--415cbacc-974b-5228-8dfc-7c2c054006aa
Feed Name: Dark Reading
Researchers disclosed an exploit chain against Mitel MiCollab that combines a path-traversal/auth-bypass (CVE-2024-41713), an older critical SQL injection (CVE-2024-35286), and an unpatched arbitrary file-read zero-day; a public proof-of-concept exists and the combined issues can let attackers read sensitive files, steal credentials, execute database/management operations, and snoop on communications across thousands of Internet-exposed devices. Both named CVEs were patched as of Oct 9, but the file-read flaw remained acknowledged and unpatched at the time of publication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
