[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Remote Code Execution Vulnerability in TrueType fonts in Microsoft Lync

Deprecated
ID: oval:org.secpod.oval:def:6055Date: (C)2012-06-19   (M)2023-12-14
Class: VULNERABILITYFamily: windows




The host is installed with Microsoft Lync 2010 or Lync 2010 Attendee and is prone to remote code execution vulnerability. A flaw is present in applications, which fail to handle shared content that contains specially crafted TrueType fonts. Successful exploitation allows remote attackers to install programs or view or change or delete data or create new accounts with full user rights.

Platform:
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Product:
Microsoft Lync 2010
Microsoft Lync 2010 Attendee
Reference:
CVE-2011-3402
CVE    1
CVE-2011-3402
CPE    3
cpe:/a:microsoft:lync_attendee:2010:user_level
cpe:/a:microsoft:lync:2010
cpe:/a:microsoft:lync_attendee:2010:admin_level

© SecPod Technologies