CVE-2018-8311
high · 8.8A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail to properly sanitize specially crafted content, aka "Remote Code Execution Vulnerability in Skype For Business and Lync." This affects Skype, Microsoft Lync.
8.8
CVSS
16.4%
EPSS (exploit prob.)
97th
EPSS percentile
2018-07-11
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | lync | all versions |
| microsoft | skype_for_business | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/104624
- http://www.securitytracker.com/id/1041259
- http://www.securitytracker.com/id/1041260
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8311
- http://www.securityfocus.com/bid/104624
- http://www.securitytracker.com/id/1041259
- http://www.securitytracker.com/id/1041260
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8311
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-8311