Security Feature Bypass in Skype for Business and Lync by Microsoft
CVE-2018-8238
What is CVE-2018-8238?
A security feature bypass vulnerability has been identified in Skype for Business and Lync, where the applications fail to accurately process UNC path links shared in messages. This flaw can potentially allow unauthorized access to sensitive information, enabling attackers to exploit the flaw by sending specially crafted links within chat messages. Users of these platforms should be aware of this vulnerability to mitigate risks associated with potential information disclosure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Microsoft Lync 2013 Service Pack 1 (32-bit)
Microsoft Lync 2013 Service Pack 1 (64-bit)
Skype Business 2016 (32-bit)
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved