Evidence of chained exploitation of path traversal vulnerabilities affecting Mitel MiCollab following public release of proof-of-concept code
Summary
Evidence of chained exploitation of path traversal vulnerabilities affecting Mitel MiCollab following public release of proof-of-concept code
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
After proof-of-concept technical details were published on 5 December 2024 for CVE-2024-41713 and CVE-2024-55550, exploitation activity chaining these two Mitel MiCollab vulnerabilities has been reported.
MiCollab is a cloud-based platform that integrates chat, voice, video, and SMS messaging for teams.
Vulnerability details
Remediation advice
Affected organisations must review the following Mitel Product Security Advisory MISA-2024-0029 for more information and update to MiCollab 9.8 SP2 (9.8.2.12) or later.
Remediation steps
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 12 December 2024 10:25 am