Lync 2013 / SfB 2015 Client Security Update – April 2016

This week’s security update takes the Office 2013-based Lync/SfB client from 15.0.4805.1000 to 15.0.4809.1000.

Kb3114944 “MS16-039: Description of the security update for Lync 2013 (Skype for Business): April 12, 2016.

This security update resolves vulnerabilities in Microsoft Lync 2013 and Skype for Business. The vulnerabilities could allow remote code execution if a user opens a specially crafted document or visits a webpage that contains specially crafted embedded fonts.To learn more about the vulnerabilities, see Microsoft Security Bulletin MS16-039.

For a complete list of affected software, see Microsoft Knowledge Base article 3148522“.

 

What’s Fixed

This security update contains fixes for the following security issue:

  •  3153357 Buffer may overrun when you use Lync 2013 or Skype for Business

This security update also contains fixes for the following nonsecurity issues:

  •  3153356 Can’t join a Lync online’s audio/video meeting in Skype for Business that has a proxy server set

What’s New / Changed

None documented.

Known Issues

None documented.

Pre-Req’s

There are no changes here from recent updates, so if you’re already current you only need the patch itself, below under “Download”.

If however your patching isn’t to current, then you’ll need to check you have *all* of these pre-req’s. The Office 2013 SP1 requirement still applies if you’re using Outlook 2010. (Lync 2013 in all of its flavours – e.g. Lync Basic – is still a component of Office 2013).

Update

Download

Current Version

Released

Update for Office 2013 (KB3054853) (NOTE 1 BELOW) 1.0 9 June 2015
LyncHelpLoc (Kb3039776) 1.0 1 December 2015
Microsoft Office 2013 Language Pack Service Pack 1 (KB2817427) 1.0 13 February 2014

NOTE1: “You do not have to apply update KB3054853 if you applied the April 14, 2015, update (KB2889923) or the May 12, 2015, security update (KB3039779) for Lync 2013 (Skype for Business)”

Download

This is the client fix itself:

  • x86 (lync2013-kb3114944-fullfile-x86-glb.exe)
  • x64 (lync2013-kb3114944-fullfile-x64-glb.exe)

Reboot

I have all the pre-req’s already installed, so a reboot was not required. I was however running Outlook 2013 at the time and I was prompted to exit it, to which I duly complied.

Before / After

Before

After

SfB 15.0.4805.1000 MSO 15.0.4815.1000 SfB 15.0.4809.1000 MSO 15.0.4815.1000
Lync2013ClientApril2016Update-Before Lync2013ClientApril2016Update-After

 

Revision History

16th April 2016: This is the initial post
11th June 2016: Corrected download links

 

– G.

Leave a Reply

Your email address will not be published.

... and please just confirm for me that you're not a bot first: Time limit is exhausted. Please reload the CAPTCHA.

This site uses Akismet to reduce spam. Learn how your comment data is processed.