Skip to main content

Microsoft Lync Server Denial of Service Vulnerabilities

Last Update Date: 10 Sep 2014 12:41 Release Date: 10 Sep 2014 2822 Views

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers
  1. Lync Denial of Service Vulnerability
    A denial of service vulnerability exists in Lync Server. An attacker who successfully exploited this vulnerability could cause the affected system to stop responding.
  2. Lync XSS Information Disclosure Vulnerability
    A reflected cross-site scripting (XSS) vulnerability, which could result in information disclosure, exists when Lync Server fails to properly sanitize specially crafted content. An attacker who successfully exploited this vulnerability could potentially execute scripts in the user’s browser to obtain information from web sessions.

Impact

  • Cross-Site Scripting
  • Denial of Service
  • Information Disclosure

System / Technologies affected

  • Microsoft Lync Server 2010
  • Microsoft Lync Server 2013

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link