CVE-2018-8238: Microsoft Lync

High severity, CVSS 7.8. EPSS: 5.8% chance of exploitation in the next 30 days.

A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync.

Affected products

Published 2018-07-11. Last modified 2026-06-17.