vendor:
Skype for Business 2016
by:
@nyxgeek - TrustedSec
5,4
CVSS
MEDIUM
XSS Injection
79
CWE
Product Name: Skype for Business 2016
Affected Version From: 16.0.7830.1018 32-bit & 16.0.7927.1020 64-bit or lower
Affected Version To: 16.0.7830.1018 32-bit & 16.0.7927.1020 64-bit or lower
Patch Exists: YES
Related CWE: CVE-2017-8550
CPE: a:microsoft:skype_for_business_2016
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Skype for Business 2016 XSS Injection – CVE-2017-8550
XSS injection is possible via the Lync 2013 SDK and PowerShell. No user-interaction is required for the XSS to execute on the target machine. It will run regardless of whether or not they accept the message. The target only needs to be online. Additionally, by forcing a browse to a UNC path via the file URI it is possible to capture hashed user credentials for the current user.
Mitigation:
Install the latest version of Skype for Business 2016 and ensure that the Lync 2013 SDK is installed and up to date.