Microsoft Lync Server 2010 does not correctly reject the SUBSCRIBE request that is received when the value of the ms-source-verified-user parameter is unverified. Therefore, the Lync Server 2010 server cannot prevent spam instant message (SPIM) attacks that come from public IM clients, such as Windows Live Messenger, AOL, or Yahoo. Additionally, the public IM client users can verify the presence status, and send an instant message to Office Communicator 2007 R2 users.
Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.