CVE-2012-1849: Critical severity Microsoft Lync vulnerability
Published Jun 12, 2012
·Updated
Untrusted search path vulnerability in Microsoft Lync 2010, 2010 Attendee, and 2010 Attendant allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .ocsmeet file, aka "Lync Insecure Library Loading Vulnerability."
Affected Software
5 affected components
Microsoft Lync=2010
Microsoft Lync=2010
Microsoft Lync=2010
Microsoft Lync=2010
Microsoft Lync=2010
Event History
Jun 12, 2012
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1849?
CVE-2012-1849 is rated as important, allowing local users to gain elevated privileges.
2
How do I fix CVE-2012-1849?
To remediate CVE-2012-1849, users should apply the latest security updates provided by Microsoft.
3
Which applications are affected by CVE-2012-1849?
CVE-2012-1849 affects Microsoft Lync 2010, including the Attendee and Attendant versions.
4
Can CVE-2012-1849 be exploited remotely?
No, CVE-2012-1849 requires local access to exploit the vulnerability.
5
What type of vulnerability is CVE-2012-1849?
CVE-2012-1849 is classified as an untrusted search path vulnerability.