Improper input validation in Microsoft Lync and Skype for Business - CVE-2018-8238
Published: July 10, 2018 / Updated: July 10, 2018
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to improper validation of UNC path links shared via messages. A remote attacker can construct a specially crafted link to file, trick the victim into clicking on that link and execute arbitrary code on the target system with privileges of the current user.
Affected software
Skype for Business