HomeSecurityPoC exploit released for zero-day vulnerability in Mitel MiCollab

PoC exploit released for zero-day vulnerability in Mitel MiCollab

Security researchers have discovered a zero-day vulnerability in the Mitel MiCollab collaboration platform, which allows attackers to access files in a server's filesystem.

Mitel MiCollab zero-day PoC exploit

Mitel MiCollab is an enterprise collaboration platform that unifies various communication tools into one application. It offers various capabilities, such as voice and video calls, messaging, audio conferencing, group collaboration features, and more.

The zero-day vulnerability was discovered by watchTowr, who notified Mitel of its existence in August. However, it has not yet been patched.

See also: Zero-day flaws in IO-Data router exploited in attacks

“ watchTowr contacted Mitel on August 26th about the new vulnerability. Mitel informed WatchTowr of its plans to patch it in the first week of December 2024. At the time of publication, there is no update on the Mitel Security Advisory page ,” the researchers explained

Mitel MiCollab: How was the new zero-day vulnerability discovered?

The vulnerability was discovered during the investigation of previous vulnerabilities in the MiCollab platform.

Specifically, the researchers were studying CVE-2024-35286, an SQL injection bug that Mitel patched on May 23, and CVE-2024-41713, an authentication bypass that was patched on October 9.

The zero-day vulnerability was discovered during the detection of the “ReconcileWizard” servlet, with injections of a path traversal string into the “reportName” parameter of an XML-based API request.

This resulted in researchers gaining access to files containing sensitive information about accounts in a system.

See also: Hackers use Zero-Day attacks to evade security tools

It is worth noting that a proof-of-concept (PoC) exploit showing how this zero-day vulnerability can be used in the Mitel MiCollab platform. This means that Mitel must act immediately and release a patch.

The researchers noted that the vulnerability in question is technically less critical than the other two, but remains a significant threat, as it allows unauthorized users to access sensitive system files.

PoC exploit released for zero-day vulnerability in Mitel MiCollab

Ways of protection

Since the vulnerability has not yet been patched, organizations using MiCollab should immediately implement some measures that can help:

  • Restrict access to the MiCollab server (only to trusted IP ranges or internal networks).
  • Apply firewall rules
  • Monitor logs for suspicious activity
  • Watch for unexpected access to sensitive files or configuration data.
  • If possible, disable or restrict access to the ReconcileWizard servlet.
  • Apply the latest version of Mitel MiCollab. It does not address this zero-day vulnerability, but it protects against other recent bugs.

What are the latest techniques for dealing with Zero-Day vulnerabilities?

One of the most modern techniques for dealing with Zero-Day vulnerabilities is the use of artificial intelligence and machine learning to detect and prevent these attacks. These technologies can analyze large volumes of data and identify patterns that could indicate a potential attack.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, the use of intrusion detection systems (IDS) and intrusion prevention systems (IPS) is another modern technique for dealing with Zero-Day vulnerabilities. These systems can identify and address threats before they affect the system.

See also: RomCom hackers exploit two zero-day vulnerabilities in Firefox and Windows

Finally, continuous updating and monitoring of systems is essential to protect against Zero-Day vulnerabilities. Updating software and security systems with the latest versions can help prevent attacks, while monitoring systems can allow for the immediate detection and response to any breaches.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS