cbcvebase.
CVE-2021-24099
published 2021-02-25

CVE-2021-24099: Skype for Business and Lync Denial of Service Vulnerability

PriorityP429medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
2.89%
85.4th percentile
Skype for Business and Lync Denial of Service Vulnerability

Affected

9 ranges
VendorProductVersion rangeFixed in
microsoftlync_server
microsoftmicrosoft_lync_server_2013< publicationpublication
microsoftskype_for_business_server
microsoftskype_for_business_server
microsoftskype_for_business_server_2015_cu_8>= 2015 CU 8 < publicationpublication
microsoftskype_for_business_server_2019_cu2>= 7.0.0 < publicationpublication
msrcmicrosoft_lync_server_2013
msrcskype_for_business_server_2015_cu_8
msrcskype_for_business_server_2019_cu2

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.