CVE-2022-33633HighCVSS 7.2

Skype for Business and Lync Remote Code Execution Vulnerability

Published
July 12, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, privileges required is high (PR:H). What privileges are needed by the attacker and how are they used in the context of the remote code execution? To successfully exploit this vulnerability, the attacker must have write access on the file share, and an active file share administrator account on the target server. With write access, the attacker would need to modify specific files on the target server to trigger code execution.

🎯 Affected products3

  • Microsoft Lync Server 2013 CU10
  • Skype for Business Server 2015 CU12
  • Skype for Business Server 2019 CU6

✅ Remediation

KB5016714 (Security Update) — fixed build 8308.1198 KB5016714 (Security Update) — fixed build 9319.634 KB5016714 (Security Update) — fixed build 2046.404

🔗 References (5)