PT-2017-3101 · Microsoft · Skype For Business+1

Publicado

2017-10-10

·

Atualizado

2019-10-03

·

CVE-2017-11786

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Skype for Business versions in Microsoft Lync 2013 SP1 and Skype for Business 2016
Description The issue is related to how Skype for Business handles authentication requests, allowing an attacker to steal an authentication hash that can be reused elsewhere. This is due to insufficient access restrictions in the software. An attacker can exploit this issue by using a specially crafted user profile to steal the authentication hash code, which can then be reused.
Recommendations For Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016, consider restricting access to authentication requests until a fix is available. As a temporary workaround, consider disabling the authentication request handling functionality until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02484
CVE-2017-11786

Produtos afetados

Lync
Skype For Business