Attackers have exploited CVE-2022-29499, a critical unauthenticated remote code execution flaw in the Service Appliance component of Mitel MiVoice Connect, to gain initial access to targeted environments. The vulnerability was caused by insufficient input validation in a diagnostic script, allowing crafted requests to inject commands on exposed appliances. Mitel disclosed the issue in April and released patches in early June, after which security researchers reported active intrusion activity tied to the flaw.
Reports from Rapid7 and CrowdStrike said the vulnerability was used in real-world compromises, including a limited number of successful intrusions, though there was no indication of broad internet-scale exploitation or widespread ransomware abuse at the time. Defenders were urged to patch immediately, keep MiVoice Connect Service Appliances off the public internet where possible, and strengthen network filtering and least-privilege controls to reduce the risk of command execution and follow-on compromise.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CrowdStrike published an analysis describing a ransomware intrusion attempt that used CVE-2022-29499 as the initial access vector. The write-up publicly documented exploitation of the Mitel vulnerability.
Mitel released fixes for CVE-2022-29499 in early June 2022. The patches addressed the critical command injection issue affecting MiVoice Connect Service Appliance deployments.
Mitel published a security advisory for CVE-2022-29499, a critical remote code execution flaw in the Service Appliance component of MiVoice Connect. At the time of disclosure, the vulnerability was unpatched.
Rapid7 made a remote version-based vulnerability check available for InsightVM and Nexpose customers to assess exposure to CVE-2022-29499. The check was released the day after Rapid7's blog post.
CrowdStrike detected a ransomware intrusion attempt that used CVE-2022-29499 as an initial access vector while the flaw was still an undisclosed zero-day. Rapid7 also observed a small number of intrusions leveraging the same vulnerability for initial access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.