« Volver al listado

CVE-2022-33633

Estado: ModificadaAlta (7.2)—

Skype for Business and Lync Remote Code Execution Vulnerability

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-33633",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-33633",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-03T14:09:23.169275Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Microsoft Lync Server 2013 CU10",
          "versions": [
            {
              "status": "affected",
              "version": "8308.0",
              "lessThan": "8308.1198",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Skype for Business Server 2015 CU12",
          "versions": [
            {
              "status": "affected",
              "version": "9319.0",
              "lessThan": "9319.634",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Skype for Business Server 2019 CU6",
          "versions": [
            {
              "status": "affected",
              "version": "2046.0",
              "lessThan": "2046.404",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Unknown"
          ]
        }
      ]
    }
  ],
  "published": "2022-07-12T23:15:12.223",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-33633",
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-33633",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Skype for Business and Lync Remote Code Execution Vulnerability"
    },
    {
      "lang": "es",
      "value": "Una Vulnerabilidad de Ejecución de Código Remota en Skype for Business y Lync"
    }
  ],
  "lastModified": "2026-06-17T04:49:09.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:lync_server:2013:cumulative_update_10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33F380C0-651D-4ACF-B729-8A05EC5D5AA4"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:skype_for_business:2015:cumulative_update_12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D99EAF6C-04B7-4F2D-89B5-36C2DCE10104"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:skype_for_business:2019:cumulative_update_6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CAED0DA-EEDB-448A-81EF-AE3E3A18757E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}