Lucene search

K
kasperskyKaspersky LabKLA10609
HistorySep 09, 2014 - 12:00 a.m.

KLA10609 Multiple vulnerabilities in Microsoft Lync Server

2014-09-0900:00:00
Kaspersky Lab
threats.kaspersky.com
26

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.9 Medium

AI Score

Confidence

High

0.846 High

EPSS

Percentile

98.5%

Multiple serious vulnerabilities have been found in Microsoft Lync Server. Malicious users can exploit these vulnerabilities to inject arbitrary code or cause denial of service.

Below is a complete list of vulnerabilities

  1. XSS vulnerability can be exploited remotely via a specially designed URL;
  2. Improper exceptions handling can be exploited remotely via a specially designed call;
  3. An unknown vulnerability can be exploited remotely via a specially designed request.

Original advisories

CVE-2014-4071

CVE-2014-4070

CVE-2014-1823

CVE-2014-4068

Related products

Microsoft-Lync-Server

CVE list

CVE-2014-4071 critical

CVE-2014-4070 warning

CVE-2014-1823 warning

CVE-2014-4068 critical

KB list

2992965

2963286

2990928

2963288

2969258

2982388

2982389

2986072

2982385

2982390

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • CI

Code injection. Exploitation of vulnerabilities with this impact can lead to changes in target code.

Affected Products

  • Microsoft Lync Server 2010 and 2013

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.9 Medium

AI Score

Confidence

High

0.846 High

EPSS

Percentile

98.5%