Known Vulnerabilities for Lync by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Lync" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-1025 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly hand... | 9.8 - CRITICAL | 2020-07-14 | 2024-01-09 |
| CVE-2019-1209 | An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'. | 6.5 - MEDIUM | 2019-09-11 | 2019-09-12 |
| CVE-2019-1084 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printa... | 6.5 - MEDIUM | 2019-07-15 | 2020-05-04 |
| CVE-2018-8546 | A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerabi... | 5.9 - MEDIUM | 2018-11-14 | 2020-08-24 |
| CVE-2018-8311 | A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail to properly sanitize spe... | 8.8 - HIGH | 2018-07-11 | 2018-09-10 |
| CVE-2018-8238 | A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared vi... | 7.8 - HIGH | 2018-07-11 | 2019-10-03 |
| CVE-2017-0283 | Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,... | 8.8 - HIGH | 2017-06-15 | 2019-10-03 |
| CVE-2017-0108 | The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP... | 7.8 - HIGH | 2017-03-17 | 2017-08-16 |
| CVE-2017-0073 | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Window... | 4.3 - MEDIUM | 2017-03-17 | 2023-03-31 |
| CVE-2017-0060 | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Window... | 5.5 - MEDIUM | 2017-03-17 | 2023-03-31 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Lync | 2013 | All | All | All |
| Application | Microsoft | Lync | 2013 | - | x64 | All |
| Application | Microsoft | Lync | 2013 | - | x86 | All |
| Application | Microsoft | Lync | 2013 | sp1 | All | All |
| Application | Microsoft | Lync | 2010 | All | All | All |
| Application | Microsoft | Lync | 2010 | All | attendant_x64 | All |
| Application | Microsoft | Lync | 2010 | All | attendant_x86 | All |
| Application | Microsoft | Lync | 2010 | All | attendee | All |
| Application | Microsoft | Lync | 2010 | All | x64 | All |
| Application | Microsoft | Lync | 2010 | All | x86 | All |