CVE-2024-35315: Code Injection
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary code with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35315?
CVE-2024-35315 is classified as a privilege escalation vulnerability which can have a significant impact on affected systems.
How do I fix CVE-2024-35315?
To mitigate CVE-2024-35315, users should upgrade to the latest version of Mitel MiCollab or MiVoice Business Solution Virtual Instance that addresses the vulnerability.
Who is affected by CVE-2024-35315?
CVE-2024-35315 affects Mitel MiCollab up to version 9.7.1.110 and all versions of Mitel MiVoice Business Solution Virtual Instance.
What attacks can be executed through CVE-2024-35315?
CVE-2024-35315 allows an authenticated attacker to perform privilege escalation attacks due to improper file validation.
Is CVE-2024-35315 a remote or local vulnerability?
CVE-2024-35315 requires local access as it is an authenticated privilege escalation vulnerability.