Buffer overflow in Microsoft products - CVE-2020-1025
Published: July 14, 2020 / Updated: July 15, 2020
Skype for Business Server
Microsoft Lync
Microsoft SharePoint Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. A local user can modify the token, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.