Impact
DigitalCanion reported that Mitel MiVoice Office 400 processes a shared object with a predictable name and does not verify the file’s origin or integrity before loading it. An attacker who provides a malicious shared object bearing the expected name can cause a privileged process to import it. The module code then executes with the same privileges as that process, enabling the attacker to run arbitrary commands and gain complete control of the affected Linux virtual machine.
Affected Systems
The flaw exists in the Mitel MiVoice Office 400 platform deployed on Linux virtual machines. No individual product versions are singled out in the advisory, implying that any installation using the vulnerable module loading routine is susceptible.
Risk and Exploitability
The CVSS base score of 8.4 signals a high severity for arbitrary code execution. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires write access to the directory where the module is stored or the ability to trick a privileged process into loading the object. Because the module loading is not accompanied by origin checks, an attacker with local or privileged access could place a crafted .so file and trigger the import, resulting in full compromise of the host operating system.
OpenCVE Enrichment