Full Disclosure: Microsoft Lync for Mac 2011 susceptible…
ID: 2405fb12-90b3-5725-b63f-b9d746413a58
STIX ID: report--2405fb12-90b3-5725-b63f-b9d746413a58
Feed Name: TrustedSec blog
Threat Score
This report describes a forced-browsing vulnerability (CVE-2018-8474) in Microsoft Lync for Mac 2011 that allows an attacker to send a crafted instant message containing an <iframe> which causes the target's default browser to open a URL without user interaction; the author provides a PowerShell-based PoC, setup instructions, disclosure timeline with Microsoft, and mitigation recommendations (restrict federation, patch/manage Mac clients).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
