CVE-2018-8238
HIGHSkype for Business and Lync - Security Feature Bypass via UNC Path Link Parsing
Title source: llmDescription
A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/104619
Patch, Vendor Advisory x_refsource_confirm
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8238
Scores
CVSS v3
7.8
EPSS
0.0546
EPSS Percentile
91.9%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
Status
published
Products (2)
microsoft/lync
2013 sp1
microsoft/skype_for_business
2016
Published
Jul 11, 2018
Tracked Since
Feb 18, 2026