Microsoft Lync Server Denial of Service Vulnerabilities
Last Update Date:
10 Sep 2014 12:41
Release Date:
10 Sep 2014
3645
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
- Lync Denial of Service Vulnerability
A denial of service vulnerability exists in Lync Server. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding. - Lync XSS Information Disclosure Vulnerability
A reflected cross-site scripting (XSS) vulnerability, which could result in information disclosure, exists when Lync Server fails to properly sanitize specially crafted content. An attacker who successfully exploited this vulnerability could potentially execute scripts in the user’s browser to obtain information from web sessions.
Impact
- Cross-Site Scripting
- Denial of Service
- Information Disclosure
System / Technologies affected
- Microsoft Lync Server 2010
- Microsoft Lync Server 2013
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS14-055
Vulnerability Identifier
Source
Related Link
Share with