VulnerabilityModified
CVE-2018-8474
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.
HIGH 7.5EPSS 38.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 38.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 38.18% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/lync for mac
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/105268Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041633Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8474Vendor Advisory
- https://www.exploit-db.com/exploits/45936/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/105268Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041633Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8474Vendor Advisory
- https://www.exploit-db.com/exploits/45936/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.