Skip to main content

Microsoft Lync Multiple Vulnerabilities

Last Update Date: 13 Jun 2012 15:21 Release Date: 13 Jun 2012 4075 Views

RISK: Medium Risk

TYPE: Clients - Im, Chat & Voip

TYPE: Im, Chat & Voip
  1. TrueType Font Parsing Vulnerability
    A remote code execution vulnerability exists in the way that affected components handle shared content that contains specially crafted TrueType fonts. The vulnerability could allow remote code execution if a user views shared content that contains specially crafted TrueType fonts. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  2. TrueType Font Parsing Vulnerability
    A remote code execution vulnerability exists in the way that affected components handle shared content that contains specially crafted TrueType fonts. The vulnerability could allow remote code execution if a user views shared content that contains specially crafted TrueType fonts. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  3. Lync Insecure Library Loading Vulnerability
    A remote code execution vulnerability exists in the way that Microsoft Lync handles the loading of DLL files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  4. HTML Sanitization Vulnerability
    An information disclosure vulnerability exists in the way that HTML is filtered that could allow an attacker to perform cross-site scripting attacks and run script in the security context of the current user.

Impact

  • Remote Code Execution
  • Information Disclosure

System / Technologies affected

  • Microsoft Communicator 2007 R2
  • Microsoft Lync 2010

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 


Vulnerability Identifier


Source

 


Related Link