105268vdb entry
http://www.securityfocus.com/bid/105268 CVE-2018-8474
HIGH
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
Record summary
CVE-2018-8474 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit.
Description
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Microsoft LyncBrowse Microsoft / Microsoft Lync | CVE List | Mac 2011 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Lync for Mac 2011 - Injection Forced Browsing/DownloadExploitDB exploitby nyxgeekNot analyzed1 file
References
51041633vdb entry
http://www.securitytracker.com/id/1041633 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-8474 portal.msrc.microsoft.comConfirmation
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8474 45936exploit
https://www.exploit-db.com/exploits/45936