Beschreibung
An improper information sanitization was found in Microsoft Lync and Skype for Business. By exploiting this vulnerability malicious users can execute arbitrary code or obtain sensitive information. This vulnerability can be exploited remotely via a specially designed message.
Technical details
This vulnerability can be triggered via specially designed JavaScript content in message. It can be used to execute arbitrary HTML & JS content in vulnerable application context, open webpage via default browser or potentially trigger URIs, defined by other applications.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2015-6061 warning
KB Liste
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com