Description
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.
In plain language
AI Worth attentionCVE-2018-8474 is a flaw in Microsoft Lync for Mac 2011 where a remote attacker can send specially crafted messages to bypass built-in protections, and since it’s reachable by default, you should act if you still use this version.
CVE-2018-8474 is a security feature bypass in Microsoft Lync for Mac 2011 where network-delivered specially crafted messages can evade client security controls without authentication or user interaction, potentially enabling unauthorized access or information disclosure.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-8474 and every CVE in our database. Create a free account — no credit card required.
Create Free Account