Skip to main content

Microsoft Lync Remote Code Execution Vulnerability

Last Update Date: 15 May 2013 14:25 Release Date: 15 May 2013 3324 Views

RISK: Medium Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A remote code execution vulnerability exists when the Lync control attempts to access an object in memory that has been deleted. An attacker could exploit the vulnerability by convincing a target user to accept an invitation to launch specially crafted content within a Lync or Communicator session. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Communicator 2007 R2
  • Microsoft Lync 2010
  • Microsoft Lync 2010 Attendee
  • Microsoft Lync Server 2013

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link