logo

Bypass Bug Revives Critical N-Day in Mitel MiCollab

ID: 415cbacc-974b-5228-8dfc-7c2c054006aa

STIX ID: report--415cbacc-974b-5228-8dfc-7c2c054006aa

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-12-05

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Researchers disclosed an exploit chain against Mitel MiCollab that combines a path-traversal/auth-bypass (CVE-2024-41713), an older critical SQL injection (CVE-2024-35286), and an unpatched arbitrary file-read zero-day; a public proof-of-concept exists and the combined issues can let attackers read sensitive files, steal credentials, execute database/management operations, and snoop on communications across thousands of Internet-exposed devices. Both named CVEs were patched as of Oct 9, but the file-read flaw remained acknowledged and unpatched at the time of publication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.