Known vulnerabilities in Microsoft Lync

Vendor: Microsoft
Software CPE: cpe:2.3:a:microsoft:microsoft_lync:*:*:*:*:*:*:*:*
Total vulnerabilities: 36
Public exploits: 15
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Microsoft Lync Microsoft Lync is affected by 36 known vulnerabilities: 2 critical, 15 high, 7 medium, 12 low Critical High Medium Low

Vulnerabilities (36)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU62256 - Exposure of sensitive information to an unauthorized actor
CVE-2022-26911
CWE-200 Medium
No
No
- 12.04.2022 SB2022041260
#VU53103 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-26421
CWE-451 Medium
No
No
- 11.05.2021 SB2021051122
#VU53102 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-26422
CWE-94 Low
No
No
- 11.05.2021 SB2021051122
#VU50487 - Improper input validation
CVE-2021-24099
CWE-20 Medium
No
No
- 09.02.2021 SB2021020944
#VU50486 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-24073
CWE-451 Low
No
No
- 09.02.2021 SB2021020944
#VU29729 - Memory corruption
CVE-2020-1025
CWE-119 Low
No
No
- 14.07.2020 SB2020071415
#VU19080 - Improper input validation
CVE-2019-1084
CWE-20 Low
No
No
- 10.07.2019 SB2019071001
#VU15848 - Improper input validation
CVE-2018-8546
CWE-20 Low
No
No
- 13.11.2018 SB2018111317
#VU13787 - Memory corruption
CVE-2018-8311
CWE-119 High
No
No
- 10.07.2018 SB2018071022
#VU13789 - Improper input validation
CVE-2018-8238
CWE-20 Medium
No
No
- 10.07.2018 SB2018071022
#VU8757 - Permissions, Privileges, and Access Controls
CVE-2017-11786
CWE-264 Low
No
No
- 10.10.2017 SB2017101004
SB2017101020
#VU8303 - Exposure of sensitive information to an unauthorized actor
CVE-2017-8676
CWE-200 Low
No
No
- 12.09.2017 SB2017091220
#VU8307 - Exposure of sensitive information to an unauthorized actor
CVE-2017-8695
CWE-200 Medium
No
No
- 12.09.2017 SB2017091219
#VU8316 - Memory corruption
CVE-2017-8696
CWE-119 High
No
No
- 12.09.2017 SB2017091223
#VU6060 - Memory corruption
CVE-2017-0108
CWE-119 High
Available
No
- 14.03.2017 SB2017031427
SB2017031501
SB2017031502
and 4 more
#VU6045 - Exposure of sensitive information to an unauthorized actor
CVE-2017-0073
CWE-200 Low
No
No
- 14.03.2017 SB2017031501
SB2017031502
SB2017031503
and 3 more
#VU6042 - Exposure of sensitive information to an unauthorized actor
CVE-2017-0060
CWE-200 Low
Available
No
- 14.03.2017 SB2017031501
SB2017031502
SB2017031503
and 3 more
#VU961 - Missing release of memory after effective lifetime
CVE-2016-3263
CWE-401 Low
No
No
- 13.10.2016 SB2016101102
SB2016110820
#VU960 - Missing release of memory after effective lifetime
CVE-2016-3262
CWE-401 Low
No
No
- 13.10.2016 SB2016101102
SB2016110819
#VU975 - Memory corruption
CVE-2016-7182
CWE-119 Medium
Available
No
- 11.10.2016 SB2016101102
SB2016121334


Showing elements 1 - 20 out of 36