LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-41223: Mitel MiVoice Connect Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 21, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Mar 14, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-41223 to its Known Exploited Vulnerabilities catalog on Feb 21, 2023, with a federal patch deadline of Mar 14, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the application.

CVE-2022-41223 is a code injection vulnerability affecting the Director component of Mitel MiVoice Connect. An authenticated attacker who already has internal network access can execute code within the context of the application.

This matters for IT and security teams because code execution on a telephony or unified-communications platform can enable lateral movement, data access, or further compromise. Public reporting indicates the vulnerability has been used in ransomware activity, so prompt inventory and remediation are warranted.

How it works

The weakness is classified as CWE-94 (Improper Control of Generation of Code, or Code Injection). In this class of flaw, an application fails to properly neutralize or restrict code that is supplied as input, allowing that input to be interpreted and executed by the runtime or interpreter used by the software.

According to the available summary, the Director component of Mitel MiVoice Connect can be abused by an authenticated attacker who has reached the internal network. The attacker supplies crafted input that the component processes as code, resulting in execution under the privileges of the application. Exact injection vectors, request formats, or required privileges beyond authentication and internal access are not detailed here; teams must confirm those mechanics against the vendor advisory.

Am I affected? How to find it in your systems

Mitel MiVoice Connect is a unified-communications and telephony platform commonly deployed on-premises or in hybrid environments to provide voice, messaging, and related services. The vulnerable surface is specifically the Director component.

How to remediate

The primary action is to apply the updates published by Mitel for MiVoice Connect, following the vendor’s instructions exactly. CISA guidance likewise directs organizations to apply updates per the vendor.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on the requirements of this vulnerability: authentication and internal network access.

If your data may have been exposed

Actively exploited vulnerabilities, including those used in ransomware campaigns, frequently lead to data theft or further compromise. If you determine that an unpatched Director instance was reachable by authenticated internal users, treat the host as potentially compromised: isolate it, preserve forensic evidence, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMitel · MiVoice Connect
WeaknessCWE-94
Added to CISA KEVFeb 21, 2023
Federal patch deadlineMar 14, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities