← Vulnerability feed

Vulnerability record · CVE-2014-1823 · published 11 June 2014

CVE-2014-1823: Microsoft Lync Server Web Components Server XSS via crafted meeting URL

Microsoft · Lync Server

The Web Components Server in Microsoft Lync Server 2010 and 2013 fails to sanitize content, allowing reflected cross-site scripting through a crafted URL that contains a valid meeting ID. Because the URL must carry a legitimate meeting ID, an attacker needs knowledge of a valid meeting to build a working link, but once delivered the flaw lets script run in the victim's browser session on the Lync server origin.

4.3 CVSS 2.0 Medium EPSS 51% · top 1.1% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2010 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containing a valid meeting ID, aka "Lync Server Content Sanitization Vulnerability."

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityThe flaw is a reflected XSS with only partial integrity impact and no confirmed exploitation, but the high EPSS score and unauthenticated network reachability keep it worth prompt patching.

What it is

The Web Components Server in Microsoft Lync Server 2010 and 2013 fails to sanitize content, allowing reflected cross-site scripting through a crafted URL that contains a valid meeting ID. Because the URL must carry a legitimate meeting ID, an attacker needs knowledge of a valid meeting to build a working link, but once delivered the flaw lets script run in the victim's browser session on the Lync server origin.

Impact

An attacker can execute arbitrary script or HTML in the context of the Lync Web Components Server, enabling session theft, credential phishing or actions performed as the victim. The CVSS 2.0 vector shows partial integrity impact only, with no confidentiality or availability impact recorded.

Attack surface

Reachable over the network through the Web Components Server web interface; the vector AV:N/AC:M/Au:N indicates no authentication is required but some conditions must be met, and exploitation depends on a victim following the crafted URL, so user interaction is needed.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded; EPSS is high at 0.5109 (98.9th percentile), but the references are only a vendor advisory and VDB entries, with no public exploit or in-the-wild reporting noted.

What to do

  • Apply Microsoft security bulletin MS14-032 for Lync Server 2010 and 2013 as the primary fix.
  • If patching is delayed, restrict network access to the Web Components Server to trusted users and networks.
  • Validate and sanitize meeting ID and URL parameters at the web tier, and enforce output encoding on reflected content.
  • Educate users not to open unsolicited Lync meeting links, and consider link rewriting or safe-link inspection for inbound URLs.

Detection

  • Inspect web server and proxy logs for requests to Web Components Server endpoints containing script-like payloads or encoded HTML in URL parameters.
  • Alert on meeting URLs with unexpected query strings or characters outside the expected meeting ID format.
  • Monitor for anomalous client-side behavior or referrer patterns tied to Lync Web Components Server pages.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-1823 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2014-1823), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.