Microsoft Office
CVE-2018-8474 — Lync for Mac 2011 Security Feature Bypass Vulnerability
Executive Summary
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages. An attacker who successfully exploited this vulnerability could cause a targeted Lync for Mac 2011 user's system to browse to an attacker-specified website or automatically download file types on the operating system's safe file type list. For an attacker to exploit the vulnerability, a specially crafted message needs to be sent to a targeted user. The targeted user does not need to take any actions after receiving the message.
Overview
Moderate
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
EPSS Score
0.38177
probability of exploitation in the next 30 days
0.9843 percentile - updated 2026-08-14
View on FIRST.org
Exploits & PoC
No public exploit or PoC has been linked for this CVE yet. When available, references are sourced from public repositories and may be unverified or non-functional — review carefully before use.
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
Paul Burkeland of TrustedSec
References
On This Page