VYPR
High severity7.8NVD Advisory· Published Jul 11, 2018· Updated Jun 17, 2026

CVE-2018-8238

CVE-2018-8238

Description

A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync.

Affected products

6
  • Microsoft/Skypecpe-rescue
    Range: Business 2016 (32-bit)
  • Microsoft/Lynccpe-rescue3 versions
    2013 Service Pack 1 (32-bit)+ 2 more
    • (no CPE)range: 2013 Service Pack 1 (32-bit)
    • cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.