Microsoft Lync Remote Code Execution Vulnerability
RISK: Medium Risk
TYPE: Clients - Productivity Products
A remote code execution vulnerability exists when the Lync control attempts to access an object in memory that has been deleted. An attacker could exploit the vulnerability by convincing a target user to accept an invitation to launch specially crafted content within a Lync or Communicator session. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Communicator 2007 R2
- Microsoft Lync 2010
- Microsoft Lync 2010 Attendee
- Microsoft Lync Server 2013
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/security/bulletin/ms13-041
Vulnerability Identifier
Source
Related Link
Share with