CVE-2022-26910HighCVSS 5.3

Skype for Business and Lync Spoofing Vulnerability

Published
April 12, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? An attacker could make a specially crafted network call to the target Skype for Business server, which could cause the parsing of an http request made to an arbitrary address. This could disclose IP addresses or port numbers or both to the attacker.

🎯 Affected products2

  • Skype for Business Server 2015 CU12
  • Skype for Business Server 2019 CU6

✅ Remediation

KB5012686 (Security Update) — fixed build 9319.628 KB5012686 (Security Update) — fixed build 2046.396

🔗 References (3)