CVE-2021-24073: Skype for Business and Lync Spoofing Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N/E:P/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Feb
Released
2021-02-09
EPSS Score
0.53% (percentile: 67.4%)

Affected Products (2)

Microsoft Office

  • Skype for Business Server 2015 CU 8
  • Microsoft Lync Server 2013

Security Updates (2)

Acknowledgments

Anonymous working with the Responsible Disclosure program of de Volksbank, Amit Avrahamov <a href="https://twitter.com/avr4mit">@avr4mit</a>

Revision History

  • 2021-02-09: Information published.