Microsoft Office
CVE-2018-8474 — Lync for Mac 2011 Security Feature Bypass Vulnerability
Executive Summary
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages. An attacker who successfully exploited this vulnerability could cause a targeted Lync for Mac 2011 user's system to browse to an attacker-specified website or automatically download file types on the operating system's safe file type list. For an attacker to exploit the vulnerability, a specially crafted message needs to be sent to a targeted user. The targeted user does not need to take any actions after receiving the message.
Overview
Moderate
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
EPSS Score
0.38177
probability of exploitation in the next 30 days
0.9843 percentile - updated 2026-08-14
View on FIRST.org
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
Paul Burkeland of TrustedSec
References
On This Page