CERT-In Vulnerability Note
CIVN-2015-0285
Microsoft Lync and Microsoft Skype for Business Security Bypass Vulnerability
Original Issue Date:November 12, 2015
Severity Rating: MEDIUM
Software Affected
- Skype for Business 2016 (32-bit)
- Skype for Business Basic 2016 (32-bit)
- Skype for Business 2016 (64-bit)
- Skype for Business Basic 2016 (64-bit)
- Microsoft Lync 2013 Service Pack 1 (32-bit)
- Microsoft Lync Basic 2013 Service Pack 1 (32-bit)
- Microsoft Lync 2013 Service Pack 1 (64-bit)
- Microsoft Lync Basic 2013 Service Pack 1 (64-bit)
- Microsoft Lync 2010 (32-bit)
- Microsoft Lync 2010 (64-bit)
- Microsoft Lync 2010 Attendee (user and admin level install)
- Microsoft Lync Room System (For SMART Room System and Crestron RL)
Overview
A Vulnerability has been reported in Microsoft Lync and Microsoft Skype that could allow an unauthenticated, remote attacker to disclose potentially sensitive information.
Description
This vulnerability exists in Skype and Microsoft Lync due to insufficient validation and sanitization of user-supplied input. A remote attacker could exploit this vulnerability by persuading a targeted user to join an instant messaging session and provide the user with a link that contains crafted JavaScript code.
Successful exploitation could allow the attacker to execute arbitrary JavaScript or HTML code in the security context of the affected application to disclose potentially sensitive information.
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS15-123
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-123
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=41869
Symantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=77477
Security Tracker
http://securitytracker.com/id/1034127
http://securitytracker.com/id/1034126
CVE Name
CVE-2015-6061
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|