Microsoft Skype for Business and Lync Server CVE-2019-0798 Spoofing Vulnerability
BID:107237
Info
Microsoft Skype for Business and Lync Server CVE-2019-0798 Spoofing Vulnerability
| Bugtraq ID: | 107237 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-0798 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2019 12:00AM |
| Updated: | Mar 12 2019 12:00AM |
| Credit: | Malte Batram |
| Vulnerable: |
Microsoft Skype for Business Server 2015 0 Microsoft Lync Server 2013 0 |
| Not Vulnerable: | |
Discussion
Microsoft Skype for Business and Lync Server CVE-2019-0798 Spoofing Vulnerability
Microsoft Skype for Business and Lync Server are prone to a spoofing vulnerability.
An attacker can exploit this issue to conduct spoofing attacks, execute arbitrary script code in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks and perform unauthorized actions.
Microsoft Skype for Business Server 2015 is vulnerable.
Microsoft Skype for Business and Lync Server are prone to a spoofing vulnerability.
An attacker can exploit this issue to conduct spoofing attacks, execute arbitrary script code in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks and perform unauthorized actions.
Microsoft Skype for Business Server 2015 is vulnerable.
Exploit / POC
Microsoft Skype for Business and Lync Server CVE-2019-0798 Spoofing Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Skype for Business and Lync Server CVE-2019-0798 Spoofing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Skype for Business and Lync Server CVE-2019-0798 Spoofing Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)