Lync Server
Vendor:
First CVE: May 15, 2013 · Active for 13 years
16
Total CVEs
More Total CVEs than 92% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Lync Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 15, 2013
13 years ago
Most Recent CVE
Jul 12, 2022
1,473 days ago
CVE Severity & Scoring
Lync Server16 CVEs
69%
31%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (50.0%)
Unknown8 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (43.8%)
High1 (6.3%)
Unknown8 (50.0%)
User Interaction
None5 (31.3%)
Unknown8 (50.0%)
Required3 (18.8%)
Privileges Required
Low2 (12.5%)
High2 (12.5%)
None4 (25.0%)
Unknown8 (50.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1302HIGH Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary cod | May 15, 2013 | 9.3 | 41 | NO | NO |
CVE-2014-1823MEDIUM Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2010 and 2013 allows remote attackers to inject arbitrary web script or HTML via a cr | Jun 11, 2014 | 4.3 | 35 | NO | NO |
CVE-2022-33633HIGH Skype for Business and Lync Remote Code Execution Vulnerability | Jul 12, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-26911MEDIUM Skype for Business Information Disclosure Vulnerability | Apr 15, 2022 | 6.5 | 24 | NO | NO |
CVE-2021-26422HIGH Skype for Business and Lync Remote Code Execution Vulnerability | May 11, 2021 | 7.2 | 23 | NO | NO |
CVE-2021-26421HIGH Skype for Business and Lync Spoofing Vulnerability | May 11, 2021 | 7.1 | 23 | NO | NO |
CVE-2021-24099MEDIUM Skype for Business and Lync Denial of Service Vulnerability | Feb 25, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-24073HIGH Skype for Business and Lync Spoofing Vulnerability | Feb 25, 2021 | 7.1 | 22 | NO | NO |
CVE-2019-1029MEDIUM A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability could cause Skype for Business to stop responding. Note tha | Jun 12, 2019 | 5.9 | 22 | NO | NO |
CVE-2019-0798MEDIUM A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vu | Apr 9, 2019 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Lync Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2013 | 16 | 5.9 | 10.9% | 0 | 0 |
| 2010 | 3 | 5.1 | 25.4% | 0 | 0 |