vendor:
Lync for Mac 2011
by:
@nyxgeek - TrustedSec
7.5
CVSS
HIGH
Forced Browsing/Download
20
CWE
Product Name: Lync for Mac 2011
Affected Version From: Lync:Mac 2011 14.4.3
Affected Version To: Lync:Mac 2011 14.4.3 (170308)
Patch Exists: NO
Related CWE: CVE-2018-8474
CPE: a:microsoft:lync_for_mac_2011
Other Scripts:
N/A
Platforms Tested: Mac
2018
Microsoft Lync for Mac 2011 Injection Forced Browsing/Download
Force browsing or download via embedded iframe in a chat window. No user interaction required. When the iframe contains a web site URL, a new browser window of the default browser will open with the URL. If the URL is a file, it will download it automatically if it is a permitted file type (e.g., zip)
Mitigation:
Install the Lync 2013 SDK (https://www.microsoft.com/en-us/download/details.aspx?id=36824)