CVE-2020-1025Improper Input Validation in Microsoft Lync Server 2013

Severity
9.8CRITICALNVD
EPSS
13.8%
top 5.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages11 packages

CVEListV5microsoft/skype_for_business_server_2019_cu27.0.0publication
CVEListV5microsoft/skype_for_business_server_2015_cu_82015 CU 8publication
CVEListV5microsoft/microsoft_sharepoint_server_201916.0.0publication

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5xrx-pfvm-p5p8: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation2022-05-24
CVEList
Microsoft Office Elevation of Privilege Vulnerability2020-07-14

📋Vendor Advisories

1
Microsoft
Microsoft Office Elevation of Privilege Vulnerability2020-07-14

💬Community

1
Bugzilla
CVE-2020-25650 spice-vdagent: memory DoS via arbitrary entries in active_xfers hash table2020-10-08
CVE-2020-1025 — Improper Input Validation in Microsoft | cvebase