Security Feature Bypass in Skype for Business and Lync by Microsoft
CVE-2018-8238
7.8HIGH
Summary
A security feature bypass vulnerability has been identified in Skype for Business and Lync, where the applications fail to accurately process UNC path links shared in messages. This flaw can potentially allow unauthorized access to sensitive information, enabling attackers to exploit the flaw by sending specially crafted links within chat messages. Users of these platforms should be aware of this vulnerability to mitigate risks associated with potential information disclosure.
Affected Version(s)
Microsoft Lync 2013 Service Pack 1 (32-bit)
Microsoft Lync 2013 Service Pack 1 (64-bit)
Skype Business 2016 (32-bit)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved