CVE-2019-1209
published 2019-09-11CVE-2019-1209: An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'.
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
6.20%
92.7th percentile
An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | lync | — | — |
| microsoft | microsoft_lync_server | — | — |
| msrc | microsoft_lync_server_2013 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Lync 2013 Information Disclosure Vulnerability
vendor_msrc·2019-09-10·CVSS 6.5
CVE-2019-1209 [MEDIUM] Lync 2013 Information Disclosure Vulnerability
Lync 2013 Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in Lync 2013. An attacker who exploited it could read arbitrary files on the victim's machine.
To exploit the vulnerability, an attacker needs to instantiate a conference and modify the meeting link with malicious content and send the link to a victim.
The update addresses the vulnerability by changing how the URL is being resolved.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is unauthorized file system access - reading from the file system.
Skype for Business and Microsoft Lync: Skype for Business and Microsoft Lync
Microsoft: Microsoft
Customer Ac
GHSA
GHSA-6rjq-46qf-87g8: An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'
ghsa_unreviewed·2022-05-24
CVE-2019-1209 [MEDIUM] GHSA-6rjq-46qf-87g8: An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'
An information disclosure vulnerability exists in Lync 2013, aka 'Lync 2013 Information Disclosure Vulnerability'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-09-11
Published