logo

Full Disclosure: Microsoft Lync for Mac 2011 susceptible…

ID: 2405fb12-90b3-5725-b63f-b9d746413a58

STIX ID: report--2405fb12-90b3-5725-b63f-b9d746413a58

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-25

Date Updated: 2026-05-01

...
...

This report describes a forced-browsing vulnerability (CVE-2018-8474) in Microsoft Lync for Mac 2011 that allows an attacker to send a crafted instant message containing an <iframe> which causes the target's default browser to open a URL without user interaction; the author provides a PowerShell-based PoC, setup instructions, disclosure timeline with Microsoft, and mitigation recommendations (restrict federation, patch/manage Mac clients).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.