cbcvebase.
CVE-2018-8546
published 2018-11-14

CVE-2018-8546: A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365…

PriorityP428medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
5.46%
91.9th percentile
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.

Affected

25 ranges
VendorProductVersion rangeFixed in
microsoftlync
microsoftlync_basic
microsoftmicrosoft_lync
microsoftmicrosoft_lync
microsoftmicrosoft_lync
microsoftmicrosoft_lync
microsoftmicrosoft_office
microsoftmicrosoft_office
microsoftoffice
microsoftoffice
microsoftoffice
microsoftskype
microsoftskype
microsoftskype
microsoftskype
microsoftskype_for_business
microsoftskype_for_business_basic
msrcmicrosoft_lync_2013_service_pack_1
msrcmicrosoft_lync_basic_2013_service_pack_1
msrcmicrosoft_office_2019_for_32-bit_editions
msrcmicrosoft_office_2019_for_64-bit_editions
msrcoffice_365_proplus_for_32-bit_systems
msrcoffice_365_proplus_for_64-bit_systems
msrcskype_for_business_2016
msrcskype_for_business_2016_basic

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_msrc5.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.