Vulnerability record · CVE-2014-1823 · published 11 June 2014
CVE-2014-1823: Microsoft Lync Server Web Components Server XSS via crafted meeting URL
Microsoft · Lync Server
The Web Components Server in Microsoft Lync Server 2010 and 2013 fails to sanitize content, allowing reflected cross-site scripting through a crafted URL that contains a valid meeting ID. Because the URL must carry a legitimate meeting ID, an attacker needs knowledge of a valid meeting to build a working link, but once delivered the flaw lets script run in the victim's browser session on the Lync server origin.
Description
Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2010 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing a valid meeting ID, aka "Lync Server Content Sanitization Vulnerability."
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityThe flaw is a reflected XSS with only partial integrity impact and no confirmed exploitation, but the high EPSS score and unauthenticated network reachability keep it worth prompt patching.
What it is
The Web Components Server in Microsoft Lync Server 2010 and 2013 fails to sanitize content, allowing reflected cross-site scripting through a crafted URL that contains a valid meeting ID. Because the URL must carry a legitimate meeting ID, an attacker needs knowledge of a valid meeting to build a working link, but once delivered the flaw lets script run in the victim's browser session on the Lync server origin.
Impact
An attacker can execute arbitrary script or HTML in the context of the Lync Web Components Server, enabling session theft, credential phishing or actions performed as the victim. The CVSS 2.0 vector shows partial integrity impact only, with no confidentiality or availability impact recorded.
Attack surface
Reachable over the network through the Web Components Server web interface; the vector AV:N/AC:M/Au:N indicates no authentication is required but some conditions must be met, and exploitation depends on a victim following the crafted URL, so user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded; EPSS is high at 0.5109 (98.9th percentile), but the references are only a vendor advisory and VDB entries, with no public exploit or in-the-wild reporting noted.
What to do
- Apply Microsoft security bulletin MS14-032 for Lync Server 2010 and 2013 as the primary fix.
- If patching is delayed, restrict network access to the Web Components Server to trusted users and networks.
- Validate and sanitize meeting ID and URL parameters at the web tier, and enforce output encoding on reflected content.
- Educate users not to open unsolicited Lync meeting links, and consider link rewriting or safe-link inspection for inbound URLs.
Detection
- Inspect web server and proxy logs for requests to Web Components Server endpoints containing script-like payloads or encoded HTML in URL parameters.
- Alert on meeting URLs with unexpected query strings or characters outside the expected meeting ID format.
- Monitor for anomalous client-side behavior or referrer patterns tied to Lync Web Components Server pages.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-1823 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-1823), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.