PT-2017-3101 · Microsoft · Skype For Business+1
Published
2017-10-10
·
Updated
2019-10-03
·
CVE-2017-11786
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Skype for Business versions in Microsoft Lync 2013 SP1 and Skype for Business 2016
Description
The issue is related to how Skype for Business handles authentication requests, allowing an attacker to steal an authentication hash that can be reused elsewhere. This is due to insufficient access restrictions in the software. An attacker can exploit this issue by using a specially crafted user profile to steal the authentication hash code, which can then be reused.
Recommendations
For Skype for Business in Microsoft Lync 2013 SP1 and Skype for Business 2016, consider restricting access to authentication requests until a fix is available.
As a temporary workaround, consider disabling the authentication request handling functionality until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lync
Skype For Business