Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 05 Oct 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine. | |
| Title | Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution | |
| Weaknesses | CWE-426 CWE-427 CWE-494 CWE-73 CWE-829 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NCSC.ch
Published:
Updated: 2026-10-05T12:55:24.978Z
Reserved: 2026-10-02T13:47:47.693Z
Link: CVE-2026-104809
Updated: 2026-10-05T12:55:17.723Z
Status : Received
Published: 2026-10-05T09:17:10.007
Modified: 2026-10-05T13:16:51.673
Link: CVE-2026-104809
No data.
OpenCVE Enrichment
Updated: 2026-10-05T11:15:07Z