CVE-2018-8474

high

Description

A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.

References

http://www.securityfocus.com/bid/105268

http://www.securitytracker.com/id/1041633

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8474

https://www.exploit-db.com/exploits/45936/

Details

Source: MITRE

Published: 2018-09-13

Updated: 2019-02-28

Type: CWE-20

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Impact Score: 3.6

Exploitability Score: 3.9

Severity: HIGH