#VU13789 Improper input validation in Skype for Business and Microsoft Lync - CVE-2018-8238
Published: July 10, 2018 / Updated: July 10, 2018
Skype for Business
Microsoft Lync
Microsoft
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to improper validation of UNC path links shared via messages. A remote attacker can construct a specially crafted link to file, trick the victim into clicking on that link and execute arbitrary code on the target system with privileges of the current user.