CVE Vulnerabilities

CVE-2018-8238

Published: Jul 11, 2018 | Modified: Oct 03, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka Skype for Business and Lync Security Feature Bypass Vulnerability. This affects Skype, Microsoft Lync.

Affected Software

Name Vendor Start Version End Version
Lync Microsoft 2013-sp1 (including) 2013-sp1 (including)
Skype_for_business Microsoft 2016 (including) 2016 (including)

References