Remote Code Execution Vulnerability in Skype for Business and Microsoft Lync
CVE-2018-8311

8.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
11 July 2018

Summary

A remote code execution vulnerability can occur in Skype for Business and Microsoft Lync when the clients inadequately sanitize specially crafted content. This flaw allows attackers to execute arbitrary code on the affected systems, potentially leading to unauthorized access and data compromise. Users of these applications should ensure their software is updated to mitigate this risk. For further details, users can refer to the Microsoft security advisory.

Affected Version(s)

Microsoft Lync 2013 Service Pack 1 (32-bit)

Microsoft Lync 2013 Service Pack 1 (64-bit)

Skype Business 2016 (32-bit)

References

EPSS Score

47% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.