ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Mitel MiCollab zero-day and PoC exploit unveiled

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-41713
+1 in the same advisory: …35286
Unauthenticated Path Traversal in Mitel MiCollab NuPoint Unified Messaging

CVE-2024-41713 is a path traversal vulnerability (CWE-22) in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201), caused by insufficient input validation. An unauthenticated remote attacker can send crafted requests that traverse the file system without needing credentials or user interaction. A successful exploit grants unauthorized access allowing the attacker to view, corrupt, or delete users' data and system configurations, and reporting indicates exposure to unauthorized file and administrative access. Any organization running an affected MiCollab version, particularly with the NPM component reachable from untrusted networks, is at risk. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-01-07 with known ransomware use, and EPSS places it in the top percentile with a 98.1% probability of exploitation within 30 days.

Do: Upgrade MiCollab to a release later than 9.8 SP1 FP2 (9.8.1.201) per Mitel's advisory; if patching is not immediately possible, apply the vendor's mitigations or restrict/discontinue use of the NPM component, especially where it is internet-facing, as required by the CISA KEV entry. Given known ransomware use and reported admin-access abuse, hunt for signs of exploitation on exposed MiCollab servers (unexpected file changes, configuration tampering, and follow-on lateral movement).

9.1
group max
98% KEV ransomware
  • Mitel MiCollab (NuPoint Unified Messaging component) through 9.8 SP1 FP2 (9.8.1.201)
largeon the order of tens of thousands of enterprise deployments, with thousands of MiCollab instances likely internet-exposed

Indicators of compromiseAll →

TypeIndicatorContext
ipv49.8.2.12ays. Risk mitigation Upgrading MiCollab to version 9.8 SP2 (9.8.2.12) or later or implementing a patch for releases 9.7 and abov
Full article388 words · extracted from helpnetsecurity.com · click to collapse

A zero-day vulnerability in the Mitel MiCollab enterprise collaboration suite can be exploited to read files containing sensitive data, watchTowr researcher Sonny Macdonald has disclosed, and followed up by releasing a proof-of-concept (PoC) exploit that chains together this zero-day file read vulnerability with CVE-2024-41713, which allows attackers to bypass authentication.

A zero-day and PoC to grab sensitive info of MiCollab users

In a blog post published on Thursday, Macdonald tells of watchTowr’s quest to reproduce CVE-2024-35286, a MiCollab SQL injection vulnerability fixed earlier this year, and their discovery of:

  • CVE-2024-41713, an additional authentication bypass vulnerability (which Mitel subsequently patched in October), and
  • An arbitrary file read zero-day still without a CVE number (a patch for which Mitel said would release in the first week od December 2024)

The zero-day can only be exploited by authenticated attackers, hence it getting chained with CVE-2024-41713 in the PoC. But if that requirement is achieved, attackers can navigate to and access sensitive files such as /etc/passwd.

The researchers went public with the flaw because they’ve reported it more than three months ago. Mitel with hopefully release a fix in the coming days.

Risk mitigation

Upgrading MiCollab to version 9.8 SP2 (9.8.2.12) or later or implementing a patch for releases 9.7 and above fixes CVE-2024-41713, thus crippling watchTowr’s PoC. But until Mitel fixed the CVE-less zero-day, attackers could still abuse it.

Organizations can implement the latest available patches and repeat the process when Mitel patches the zero-day. Allowing access to vulnerable servers only from trusted IP ranges and internal networks is also a good idea to minimize the risk of exploitation of these (and other flaws).

According to Macdonald, there are over 16,000 MiCollab instances across the Internet.

“MiCollab comprises a softphone application deployed to endpoints and a central server component capable of coordinating telephone calls between endpoints and also to the outside world. It’s like a mini telephone exchange, and it boasts the features you’d expect – voicemail, file sharing, and even desktop sharing so that users can show each other what they’re doing. While it’s obvious how dangerous compromise of features such as ‘desktop sharing’ are, there are usually larger dangers exposed by the telephone function itself,” he added.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/12/05/mitel-micollab-zero-day-and-poc-exploit-unveiled/