CVE-2018-8474

MEDIUM

Description

A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.

References

http://www.securityfocus.com/bid/105268

http://www.securitytracker.com/id/1041633

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8474

https://www.exploit-db.com/exploits/45936/

Details

Source: MITRE

Published: 2018-09-13

Updated: 2019-02-28

Type: CWE-20

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3.0

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:microsoft:lync_for_mac:2011:*:*:*:*:*:*:*

Tenable Plugins

View all (1 total)

IDNameProductFamilySeverity
117409Security Update for Microsoft Office (September 2018) (macOS)NessusMacOS X Local Security Checks
high