Microsoft Lync Server 2013 vulnerabilities

5 known vulnerabilities affecting microsoft/microsoft_lync_server_2013.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2021-24073HIGHCVSS 7.1fixed in publication2021-02-25
CVE-2021-24073 [HIGH] CVE-2021-24073: Skype for Business and Lync Spoofing Vulnerability Skype for Business and Lync Spoofing Vulnerability
cvelistv5nvd
CVE-2021-24099MEDIUMCVSS 6.5fixed in publication2021-02-25
CVE-2021-24099 [MEDIUM] CVE-2021-24099: Skype for Business and Lync Denial of Service Vulnerability Skype for Business and Lync Denial of Service Vulnerability
cvelistv5nvd
CVE-2020-1025CRITICALCVSS 9.8fixed in publication2020-07-14
CVE-2020-1025 [CRITICAL] CWE-20 CVE-2020-1025: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Busine An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update
cvelistv5nvd
CVE-2019-1029MEDIUMCVSS 5.9fixed in publication2019-06-12
CVE-2019-1029 [MEDIUM] CVE-2019-1029: A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploit A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability could cause Skype for Business to stop responding. Note that the denial of service would not allow an attacker to execute code or to elevate the attacker's user rights. To exploit the vulnerability, an attacker needs to obtain a dial-in lin
cvelistv5nvd
CVE-2019-0798MEDIUMCVSS 6.1vJuly 2018 Update2019-04-09
CVE-2019-0798 [MEDIUM] CWE-79 CVE-2019-0798: A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sa A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.
cvelistv5nvd