#MiCollab
PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files
PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug
Still unpatched 100+ days later, watchTowr says
www.theregister.com
December 6, 2024 at 6:11 AM
Researchers have uncovered an arbitrary file read zero-day in the Mitel MiCollab collaboration platform, allowing attackers to access files on a server's filesystem.

www.bleepingcomputer.com/news/securit...
Mitel MiCollab zero-day flaw gets proof-of-concept exploit
Researchers have uncovered an arbitrary file read zero-day in the Mitel MiCollab collaboration platform, allowing attackers to access files on a server's filesystem.
www.bleepingcomputer.com
December 5, 2024 at 6:08 PM
💡 Attackers act fast on public PoC code — sometimes within hours. On Dec 5, PoC for two Mitel MiCollab CVEs dropped, and GreyNoise immediately detected attacker activity. 🔎 Real-time intelligence is critical.
From PoC to Attacker Interest in Hours: Real-Time Insights into Mitel MiCollab Vulnerabilities | GreyNoise Blog
www.greynoise.io
December 10, 2024 at 8:13 PM
CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks.
CISA warns of critical Oracle, Mitel flaws exploited in attacks
CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks.
www.bleepingcomputer.com
January 7, 2025 at 6:45 PM
watchTowr researchers have identified a new unauthenticated path traversal vulnerability in the Mitel MiCollab VoIP platform

- CVE-2024-41713
- 9.8/10 score

labs.watchtowr.com/where-theres...
Where There’s Smoke, There’s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day
It is not just APTs that like to target telephone systems, but ourselves at watchTowr too. We can't overstate the consequences of an attacker crossing the boundary from the 'computer system' to the '...
labs.watchtowr.com
December 5, 2024 at 1:37 PM
BEC Step by Step; Mital MiCollab PoC; Lorex Camera, HPE Aruba Vuln;
https://isc.sans.edu/podcastdetail/9244
December 6, 2024 at 2:00 AM
CERTFR-2026-AVI-0411: Multiples vulnérabilités dans Mitel MiCollab
https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0411/
April 9, 2026 at 12:45 PM
Where There’s Smoke, There’s Fire - Mitel MiCollab CVE-2024-35286, CVE-2024-41713 And An 0day labs.watchtowr.com/where-theres...
December 5, 2024 at 2:05 PM
December 5, 2024 at 3:19 PM
#CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks. #cybersecurity #infosec
www.bleepingcomputer.com/news/securit...
CISA warns of critical Oracle, Mitel flaws exploited in attacks
CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks.
www.bleepingcomputer.com
January 7, 2025 at 11:57 PM
📣 We have added a new #vulnerability detection to our #ASM #AttackSurfaceManagement solution for #Mitel MiCollab product:

CVE-2024-35286: unauthenticated SQL injection on login page
CVE-2024-41713: unauthenticated arbitrary file read

www.onyphe.io/search?q=cat...
December 6, 2024 at 9:58 AM
Notícia da SecurityOnline

"Vulnerabilidade Zero-Day Sem Correção no Mitel MiCollab Exponde Negócios a Sérios Riscos de Segurança" #bolhasec
Unpatched Zero-Day Vulnerability in Mitel MiCollab Exposes Businesses to Serious Security Risks
A newly disclosed zero-day vulnerability in the Mitel MiCollab collaboration platform has raised serious concerns regarding the security of sensitive business data. Discovered by security researchers at watchTowr, the vulnerability... The post Unpatched Zero-Day Vulnerability in Mitel MiCollab Exposes Businesses to Serious Security Risks appeared first on Cybersecurity News.
securityonline.info
December 6, 2024 at 7:31 PM
CISA warns of critical Oracle, Mitel flaws exploited in attacks
CISA warns of critical Oracle, Mitel flaws exploited in attacks
CISA has warned U.S. federal agencies to secure their systems against critical vulnerabilities in Oracle WebLogic Server and Mitel MiCollab systems that are actively exploited in attacks.
www.bleepingcomputer.com
January 7, 2025 at 7:10 PM
実証コードから攻撃者が関心を持つまでの数時間: Mitel MiCollab の脆弱性に関するリアルタイムの分析
#CybersecurityNews
www.greynoise.io/blog/from-po...
From PoC to Attacker Interest in Hours: Real-Time Insights into Mitel MiCollab Vulnerabilities | GreyNoise Blog
www.greynoise.io
December 10, 2024 at 11:17 PM
PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files
PoC exploit chains Mitel MiCollab 0-day, auth-bypass bug to access sensitive files
Still unpatched 100+ days later, watchTowr says A zero-day arbitrary file read vulnerability in Mitel MiCollab can be chained with a now-patched critical bug in the same platform to give attackers access to sensitive files on vulnerable instances. …
dlvr.it
December 6, 2024 at 6:06 AM
Mitel 0-day, 5-year-old Oracle RCE bugs under active exploit
Mitel 0-day, 5-year-old Oracle RCE bugs under active exploit
3 CVEs added to CISA's catalog Cybercriminals are actively exploiting two vulnerabilities in Mitel MiCollab, including a zero-day flaw, alongside a critical remote code execution vulnerability in Oracle WebLogic Server that has been exploited for at…
dlvr.it
January 8, 2025 at 8:33 PM
CISA Alerts on Actively Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server
CISA Alerts on Actively Exploited Vulnerabilities in Mitel MiCollab and Oracle WebLogic Server
CISA issues urgent warning about actively exploited security flaws affecting Mitel and Oracle systems. Find out the risks and how to mitigate them.
securityonline.info
January 8, 2025 at 3:10 AM
A critical flaw (CVE-2024-41713) in Mitel MiCollab allows unauthorized file and admin access. WatchTowr Labs found this vulnerability, which has since been patched in version 9.8 SP2. The flaw allows attackers to bypass authentication and read files, potentially exposing sensitive data.
December 5, 2024 at 3:19 PM
Mitel MiCollab zero-day flaw gets proof-of-concept exploit
Mitel MiCollab zero-day flaw gets proof-of-concept exploit
Researchers have uncovered an arbitrary file read zero-day in the Mitel MiCollab collaboration platform, allowing attackers to access files on a server's filesystem.
www.bleepingcomputer.com
December 5, 2024 at 7:12 PM
Cybersecurity researchers have released a proof-of-concept (PoC) exploit that strings together a now-patched critical security flaw impacting Mitel MiCollab with an arbitrary file read zero-day, granting an attacker the ability to access files from susceptible instances.

tinyurl.com/Mitel-MiCollab
Critical Mitel MiCollab Flaw Exposes Systems to Unauthorized File and Admin Access
Critical Mitel MiCollab exploit CVE-2024-41713 patched; update to prevent file access and admin misuse.
thehackernews.com
December 5, 2024 at 3:45 PM