KLA10693
Information disclosure vulnerability in Microsoft Lync & Skype for Business
Updated: 06/01/2019
Detect date
?
11/10/2015
Severity
?
Warning
Description

An improper information sanitization was found in Microsoft Lync and Skype for Business. By exploiting this vulnerability malicious users can execute arbitrary code or obtain sensitive information. This vulnerability can be exploited remotely via a specially designed message.


Technical details

This vulnerability can be triggered via specially designed JavaScript content in message. It can be used to execute arbitrary HTML & JS content in vulnerable application context, open webpage via default browser or potentially trigger URIs, defined by other applications.

Affected products

Microsoft Skype for Business 2016
Microsoft Lync 2013 Service Pack 1
Microsoft Lync 2010
Microsoft Lync 2010 Attendee
Microsoft Lync Room System

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2015-6061

Impacts
?
ACE 
[?]

SUI 
[?]
Related products
Microsoft Lync
CVE-IDS
?
CVE-2015-60614.3Warning
Microsoft official advisories
Microsoft Security Update Guide
KB list

3108096
3085634
3105872
3101496
3096738
3096736
3096735