CVE-2022-26911: Skype for Business Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2022-Apr
Released
2022-04-12
EPSS Score
19.91% (percentile: 95.5%)

FAQ

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is file content.

Affected Products (3)

Microsoft Office

  • Microsoft Lync Server 2013 CU10
  • Skype for Business Server 2015 CU12
  • Skype for Business Server 2019 CU6

Security Updates (2)

Acknowledgments

<a href="https://twitter.com/rskvp93">rskvp93</a> with <a href="https://lab.viettelcybersecurity.com/">VCSLAB of Viettel Cyber Security</a>

Revision History

  • 2022-04-12: Information published.