Remote Code Execution Vulnerability in Skype for Business and Microsoft Lync
CVE-2018-8311
8.8HIGH
Summary
A remote code execution vulnerability can occur in Skype for Business and Microsoft Lync when the clients inadequately sanitize specially crafted content. This flaw allows attackers to execute arbitrary code on the affected systems, potentially leading to unauthorized access and data compromise. Users of these applications should ensure their software is updated to mitigate this risk. For further details, users can refer to the Microsoft security advisory.
Affected Version(s)
Microsoft Lync 2013 Service Pack 1 (32-bit)
Microsoft Lync 2013 Service Pack 1 (64-bit)
Skype Business 2016 (32-bit)
References
EPSS Score
47% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved