CVE-2019-0798: XSS
A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-0798?
CVE-2019-0798 is a spoofing vulnerability that exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request.
What is the severity of CVE-2019-0798?
CVE-2019-0798 has a severity rating of 6.1 (Medium).
Which software is affected by CVE-2019-0798?
CVE-2019-0798 affects Microsoft Lync Server 2013 and Microsoft Skype for Business Server 2015.
How can I fix CVE-2019-0798?
To fix CVE-2019-0798, it is recommended to apply the latest security updates provided by Microsoft.
Where can I find more information about CVE-2019-0798?
More information about CVE-2019-0798 can be found in the Microsoft Security Guidance Advisory at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0798.