Skype For Business
by Microsoft
CVEs (61)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66304 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2023-36789 | Hig | 0.47 | 7.2 | 0.02 | Oct 10, 2023 | Skype for Business Remote Code Execution Vulnerability | ||
| CVE-2023-36786 | Hig | 0.47 | 7.2 | 0.02 | Oct 10, 2023 | Skype for Business Remote Code Execution Vulnerability | ||
| CVE-2023-36780 | Hig | 0.47 | 7.2 | 0.03 | Oct 10, 2023 | Skype for Business Remote Code Execution Vulnerability | ||
| CVE-2022-33633 | Hig | 0.47 | 7.2 | 0.02 | Jul 12, 2022 | Skype for Business and Lync Remote Code Execution Vulnerability | ||
| CVE-2021-26422 | Hig | 0.47 | 7.2 | 0.02 | May 11, 2021 | Skype for Business and Lync Remote Code Execution Vulnerability | ||
| CVE-2026-66305 | Hig | 0.46 | 7.1 | 0.00 | Sep 8, 2026 | Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2022-26911 | Med | 0.43 | 6.5 | 0.04 | Apr 15, 2022 | Skype for Business Information Disclosure Vulnerability | ||
| CVE-2019-1084 | Med | 0.43 | 6.5 | 0.05 | Jul 15, 2019 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to… | ||
| CVE-2016-3209 | Med | 0.43 | 5.5 | 0.54 | Oct 14, 2016 | Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for… | ||
| CVE-2026-69642 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-66308 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | ||
| CVE-2026-66306 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-66303 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | ||
| CVE-2026-63523 | Med | 0.42 | 6.5 | 0.00 | Sep 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2021-26421 | Med | 0.42 | 6.5 | 0.01 | May 11, 2021 | Skype for Business and Lync Spoofing Vulnerability | ||
| CVE-2021-24099 | Med | 0.42 | 6.5 | 0.03 | Feb 25, 2021 | Skype for Business and Lync Denial of Service Vulnerability | ||
| CVE-2021-24073 | Med | 0.42 | 6.5 | 0.02 | Feb 25, 2021 | Skype for Business and Lync Spoofing Vulnerability | ||
| CVE-2019-0798 | Med | 0.40 | 6.1 | 0.02 | Apr 9, 2019 | A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'. | ||
| CVE-2017-8550 | Med | 0.40 | 5.4 | 0.22 | Jun 15, 2017 | A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability". |
- risk 0.49cvss 7.5epss 0.01
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
- risk 0.47cvss 7.2epss 0.02
Skype for Business Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Skype for Business Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.03
Skype for Business Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Skype for Business and Lync Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.02
Skype for Business and Lync Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.00
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
- risk 0.43cvss 6.5epss 0.04
Skype for Business Information Disclosure Vulnerability
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to…
- risk 0.43cvss 5.5epss 0.54
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for…
- risk 0.42cvss 6.5epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Skype for Business and Lync Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.03
Skype for Business and Lync Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Skype for Business and Lync Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.02
A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.
- risk 0.40cvss 5.4epss 0.22
A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".
Page 2 of 4