Microsoft
Microsoft Skype FOR Business Server: vulnerabilidades y CVE
Microsoft Skype FOR Business Server tiene 24 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses10
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-41763 | Media (5.3) | 90% | ⚠ Explotación activa | 10 oct 2023 | Skype for Business Elevation of Privilege Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69646 | Alta (8.3) | 0.32% | — | 8 sept 2026 | Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network. |
| CVE-2026-69642 | Media (6.1) | 0.41% | — | 8 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66308 | Media (6.5) | 1.1% | — | 8 sept 2026 | Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. |
| CVE-2026-66307 | Alta (7.5) | 1.2% | — | 8 sept 2026 | Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network. |
| CVE-2026-66306 | Media (6.5) | 0.92% | — | 8 sept 2026 | Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-66305 | Alta (7.1) | 0.53% | — | 8 sept 2026 | Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-66304 | Alta (7.5) | 0.97% | — | 8 sept 2026 | Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-66303 | Media (6.5) | 1.1% | — | 8 sept 2026 | Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. |
| CVE-2026-66302 | Crítica (9.8) | 0.97% | — | 8 sept 2026 | External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. |
| CVE-2026-63523 | Media (6.1) | 0.55% | — | 8 sept 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2024-20695 | Media (5.7) | 0.56% | — | 13 feb 2024 | Skype for Business Information Disclosure Vulnerability |
| CVE-2023-41763 | Media (5.3) | 90% | ⚠ Explotación activa | 10 oct 2023 | Skype for Business Elevation of Privilege Vulnerability |
| CVE-2023-36789 | Alta (7.2) | 2.4% | — | 10 oct 2023 | Skype for Business Remote Code Execution Vulnerability |
| CVE-2023-36786 | Alta (7.2) | 2.5% | — | 10 oct 2023 | Skype for Business Remote Code Execution Vulnerability |
| CVE-2023-36780 | Alta (7.2) | 2.6% | — | 10 oct 2023 | Skype for Business Remote Code Execution Vulnerability |
| CVE-2022-26911 | Media (6.5) | 3.6% | — | 15 abr 2022 | Skype for Business Information Disclosure Vulnerability |
| CVE-2022-26910 | Media (5.3) | 2.5% | — | 15 abr 2022 | Skype for Business and Lync Spoofing Vulnerability |
| CVE-2021-26422 | Alta (7.2) | 2.2% | — | 11 may 2021 | Skype for Business and Lync Remote Code Execution Vulnerability |
| CVE-2021-26421 | Alta (7.1) | 1.4% | — | 11 may 2021 | Skype for Business and Lync Spoofing Vulnerability |
| CVE-2021-24099 | Media (6.5) | 3.2% | — | 25 feb 2021 | Skype for Business and Lync Denial of Service Vulnerability |
| CVE-2021-24073 | Alta (7.1) | 1.8% | — | 25 feb 2021 | Skype for Business and Lync Spoofing Vulnerability |
| CVE-2019-0798 | Media (6.1) | 2.1% | — | 9 abr 2019 | A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'. |
| CVE-2015-2536 | Media (4.3) | 8.9% | — | 9 sept 2015 | Cross-site scripting (XSS) vulnerability in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype for Business Server… |
| CVE-2015-2531 | Media (4.3) | 11% | — | 9 sept 2015 | Cross-site scripting (XSS) vulnerability in the jQuery engine in Microsoft Lync Server 2013 and Skype for Business Server 2015 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Skype… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.