Lucene search

K
symantecSymantec Security ResponseSMNTC-104619
HistoryJul 10, 2018 - 12:00 a.m.

Microsoft Skype for Business and Lync CVE-2018-8238 Security Bypass Vulnerability

2018-07-1000:00:00
Symantec Security Response
www.symantec.com
30

EPSS

0.005

Percentile

77.2%

Description

Microsoft Skype for Business and Lync are prone to a security-bypass vulnerability. An attacker can leverage this issue to bypass certain security restrictions and perform unauthorized actions.

Technologies Affected

  • Microsoft Lync 2013 (32-bit) SP1
  • Microsoft Lync 2013 (64-bit) SP1
  • Microsoft Skype for Business 2016 (32-bit)
  • Microsoft Skype for Business 2016 (64-bit)

Recommendations

Deploy network intrusion detection systems to monitor network traffic for malicious activity.
Deploy NIDS to monitor network traffic for signs of anomalous or suspicious activity. This may indicate exploit attempts or activity that results from a successful exploit.

Run all software as a nonprivileged user with minimal access rights.
Ensure that all nonadministrative tasks, such as browsing the web and reading email, are performed as an unprivileged user with minimal access rights.

Updates are available. Please see the references or vendor advisory for more information.