CVE-2013-1302
Summary
| CVE | CVE-2013-1302 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-05-15 03:36:00 UTC |
| Updated | 2018-10-12 22:04:00 UTC |
| Description | Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability." |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Lync | 2010 | All | attendee | All |
| Application | Microsoft | Lync | 2010 | All | x64 | All |
| Application | Microsoft | Lync | 2010 | All | x86 | All |
| Application | Microsoft | Lync | 2010 | All | attendee | All |
| Application | Microsoft | Lync | 2010 | All | x64 | All |
| Application | Microsoft | Lync | 2010 | All | x86 | All |
| Application | Microsoft | Lync Server | 2013 | All | All | All |
| Application | Microsoft | Lync Server | 2013 | All | All | All |
| Application | Microsoft | Office Communicator | 2007 | r2 | All | All |
| Application | Microsoft | Office Communicator | 2007 | r2 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Updates for Multiple Vulnerabilities | US-CERT | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| Microsoft Security Bulletin MS13-041 - Important | Microsoft Docs | MS | docs.microsoft.com | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.