New Search

Vulnerability in Lync Could Allow Remote Code Execution - MS13-041

oval:org.mitre.oval:def:15952

Microsoft Communicator 2007 R2 Lync 2010 Lync 2010 Attendee and Lync Server 2013 do not properly handle objects in memory which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object aka "Lync RCE Vulnerability."

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows 8
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2003
  • Microsoft Windows 7
  • Microsoft Windows Vista
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2012
  • Microsoft Windows XP
Class:
vulnerability
Reference(s):
  • CVE-2013-1302
Product(s):
  • Microsoft Lync 2010
  • Microsoft Lync 2010 Attendee
  • Microsoft Communicator 2007 R2
  • Microsoft Lync Server 2013