Vulnerability record · CVE-2022-41223 · published 22 November 2022
CVE-2022-41223: Mitel MiVoice Connect Director database code injection
Mitel · Mivoice Connect
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) fails to sufficiently restrict database data types, allowing crafted data to be injected as code. An attacker who already holds credentials can turn that weakness into arbitrary code execution on the communications platform, which is why CISA added it to the Known Exploited Vulnerabilities catalog.
Description
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with known ransomware use and a high EPSS percentile, but exploitation requires existing high privileges and adjacent network access, which limits reach.
What it is
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) fails to sufficiently restrict database data types, allowing crafted data to be injected as code. An attacker who already holds credentials can turn that weakness into arbitrary code execution on the communications platform, which is why CISA added it to the Known Exploited Vulnerabilities catalog.
Impact
An authenticated attacker gains code execution in the context of the Director database component, with high impact to confidentiality, integrity and availability. On a telephony platform this can mean control of call handling and access to stored communications data.
Attack surface
The vector is adjacent network (AV:A) with high privileges required (PR:H) and no user interaction, so the attacker must already have valid high-level access and be positioned on the same network segment as the Director database. It is not reachable from the internet without that foothold.
Exploitation
CISA added it to KEV on 2023-02-21 with a known ransomware campaign use flag, and EPSS puts 30-day exploitation probability near 10.6 percent (95th percentile). No public exploit details are given in the record.
What to do
- Apply the Mitel security advisory 22-0008 updates; upgrade MiVoice Connect past 19.3 (22.22.6100.0) as instructed by the vendor.
- Restrict network access to the Director database component so only trusted administrative hosts on the same segment can reach it.
- Audit and reduce accounts holding the high privileges needed to reach the vulnerable component; enforce least privilege and unique credentials.
- Monitor for and block unexpected database write activity or process spawning from the Director database service.
- Treat the KEV due date as a hard deadline and verify remediation rather than relying on compensating controls alone.
Detection
- Alert on new or unusual processes spawned by the Director database service, which would indicate injected code executing.
- Baseline and monitor database write patterns for anomalous data types or payloads reaching the Director database.
- Review authentication logs for high-privilege logins to the Director component from unexpected hosts or at unusual times.
- Hunt for post-exploitation indicators tied to known ransomware activity on hosts running MiVoice Connect.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-41223 to the Known Exploited Vulnerabilities catalog on 21 February 2023 as "Mitel MiVoice Connect Code Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 14 March 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.mitel.com/support/security-advisories | Vendor Advisory |
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008 | Vendor Advisory |
| https://www.mitel.com/support/security-advisories | Vendor Advisory |
| https://www.mitel.com/support/security-advisories/mitel-product-security-advisory-22-0008 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41223 | US Government Resource |
Track CVE-2022-41223 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.