Microsoft Skype for Business Server and Microsoft Lync Information Dislcosure Vulnerability
RISK: Medium Risk
TYPE: Clients - Im, Chat & Voip
An information disclosure vulnerability exists when Skype for Business and Microsoft Lync clients improperly sanitize specially crafted content. An attacker who successfully exploited the vulnerability could execute HTML and JavaScript content in the Skype for Business or Lync context. The attacker could use this vulnerability to open a webpage using the default browser, open another messaging session with a third party, or potentially trigger URIs that are defined by other applications on the client's system.
Impact
- Information Disclosure
System / Technologies affected
- Microsoft Skype for Business 2016
- Microsoft Lync 2013
- Microsoft Lync 2010
- Microsoft Lync Room System
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS15-123
Vulnerability Identifier
Source
Related Link
Share with