External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
How could an attacker exploit this vulnerability? An unauthenticated attacker could exploit this vulnerability over the network by sending a specially crafted request that writes an attacker-controlled file to an arbitrary location on the affected server. Successful exploitation could result in the attacker executing code on the target server. No authentication or user interaction is required.
odgrso with <a href="https://gmo-cybersecurity.com/">GMO CyberSecurity by Ierae</a>, Manish Kumar, Nitish Kumar