PT-2017-3101 · Microsoft · Skype For Business+1

Published

2017-10-10

·

Updated

2019-10-03

·

CVE-2017-11786

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Skype for Business versions in Microsoft Lync 2013 SP1 and Skype for Business 2016
Description The issue is related to how Skype for Business handles authentication requests, allowing an attacker to steal an authentication hash that can be reused elsewhere. This is due to insufficient access restrictions in the software. An attacker can exploit this issue by using a specially crafted user profile to steal the authentication hash code, which can then be reused.
Recommendations For Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016, consider restricting access to authentication requests until a fix is available. As a temporary workaround, consider disabling the authentication request handling functionality until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02484
CVE-2017-11786

Affected Products

Lync
Skype For Business