Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Lync vulnerability could allow remote code execution


Report ID: MS201305005
Date Published: 15 May 2013

Criticality: Important
Compromise Type: remote-code-execution
Compromise From: remote


Affected Product/Component:

Microsoft Communicator 2007 R2
Microsoft Lync 2010
Microsoft Lync 2010 Attendee
Microsoft Lync Server 2013




Summary

A vulnerability in Microsoft Lync could allow an attacker to execute arbitrary code and take control of an affected system.



Detailed Description

Microsoft has issued a security update for Lync to address a vulnerability that could be exploited by an attacker to execute arbitrary code and take control of an affected system. The vulnerability was caused by memory corruption condition resulting from an attempt to access a deleted object in memory.

This issue has been resolved through the latest security update which introduces a modification in the way that Lync and Communicator clients handle objects in memory. Users are recommended to install this latest update to protect their system from possible exploit attempts.



CVE Reference

CVE-2013-1302



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms13-041)




Online Virus Scanner

 
Run a quick online virus scan of your computer.