Moderate EPSS 0.38177 2018-09 archive

Executive Summary

A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages. An attacker who successfully exploited this vulnerability could cause a targeted Lync for Mac 2011 user's system to browse to an attacker-specified website or automatically download file types on the operating system's safe file type list. For an attacker to exploit the vulnerability, a specially crafted message needs to be sent to a targeted user. The targeted user does not need to take any actions after receiving the message.

Overview

Moderate
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
Category Security Feature Bypass
Released Sep 11 2018
Last Updated Sep 11 2018
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.38177 — 0.9843 percentile

EPSS Score

0.38177
probability of exploitation in the next 30 days
0.9843 percentile - updated 2026-08-14
View on FIRST.org

Known Exploits

Acknowledgments

Paul Burkeland of TrustedSec