Improper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.
How could an attacker exploit this vulnerability? An attacker with access to the internal network and a certificate trusted by the deployment could exploit this vulnerability by impersonating a trusted Skype for Business server. Successful exploitation could allow the attacker to act as another user or administrator without Skype credentials or user interaction.
Yogesh Mandge