An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, and execute arbitrary native code. This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
https://github.com/sfewer-r7/LorexExploit
https://thehackernews.com/2024/12/critical-mitel-micollab-flaw-exposes.html
Source: Mitre, NVD
Published: 2024-12-03
Updated: 2026-04-15
Base Score: 6.5
Vector: CVSS2#AV:L/AC:L/Au:M/C:C/I:C/A:C
Severity: Medium
Base Score: 6.7
Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00009