Microsoft Lync Multiple Vulnerabilities
Last Update Date:
13 Jun 2012 15:21
Release Date:
13 Jun 2012
4577
Views
RISK: Medium Risk
TYPE: Clients - Im, Chat & Voip
- TrueType Font Parsing Vulnerability
A remote code execution vulnerability exists in the way that affected components handle shared content that contains specially crafted TrueType fonts. The vulnerability could allow remote code execution if a user views shared content that contains specially crafted TrueType fonts. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. - TrueType Font Parsing Vulnerability
A remote code execution vulnerability exists in the way that affected components handle shared content that contains specially crafted TrueType fonts. The vulnerability could allow remote code execution if a user views shared content that contains specially crafted TrueType fonts. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. - Lync Insecure Library Loading Vulnerability
A remote code execution vulnerability exists in the way that Microsoft Lync handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. - HTML Sanitization Vulnerability
An information disclosure vulnerability exists in the way that HTML is filtered that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the current user.
Impact
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Microsoft Communicator 2007 R2
- Microsoft Lync 2010
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/ms12-039
Vulnerability Identifier
Source
Related Link
Share with