CVE-2021-26422
published 2021-05-11CVE-2021-26422: Skype for Business and Lync Remote Code Execution Vulnerability
PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.22%
80.7th percentile
Skype for Business and Lync Remote Code Execution Vulnerability
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | lync_server | — | — |
| microsoft | microsoft_lync_server_2013_cu10 | >= 8308.0 < 8308.1144 | 8308.1144 |
| microsoft | skype_for_business_server | — | — |
| microsoft | skype_for_business_server | — | — |
| microsoft | skype_for_business_server_2015_cu11 | >= 2015 CU11 < 9319.606 | 9319.606 |
| microsoft | skype_for_business_server_2019_cu5 | >= 1.0 < 2046.369 | 2046.369 |
| msrc | microsoft_lync_server_2013_cu10 | — | — |
| msrc | skype_for_business_server_2015_cu11 | — | — |
| msrc | skype_for_business_server_2019_cu5 | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-322h-m7q9-7x4q: Skype for Business and Lync Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-26422 [HIGH] CWE-77 GHSA-322h-m7q9-7x4q: Skype for Business and Lync Remote Code Execution Vulnerability
Skype for Business and Lync Remote Code Execution Vulnerability
Microsoft
Skype for Business and Lync Remote Code Execution Vulnerability
vendor_msrc·2021-05-11·CVSS 7.2
CVE-2021-26422 [HIGH] Skype for Business and Lync Remote Code Execution Vulnerability
Skype for Business and Lync Remote Code Execution Vulnerability
Skype for Business and Microsoft Lync: Skype for Business and Microsoft Lync
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/download/details.aspx?familyid=dac7c777-fe8a-45a2-9a82-07a2e15c298f
Reference: https://www.microsoft.com/download/details.aspx?familyid=de77f3bc-efd5-4dab-a2fb-81e2894b0937
Reference: https://www.microsoft.com/download/details.aspx?familyid=0d08ed37-106a-456f-a5c6-61df22588bec
No detection rules found.
No public exploits indexed.
2021-05-11
Published