CVE-2022-26910
published 2022-04-15CVE-2022-26910: Skype for Business and Lync Spoofing Vulnerability
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.25%
80.9th percentile
Skype for Business and Lync Spoofing Vulnerability
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | skype_for_business_server | — | — |
| microsoft | skype_for_business_server | — | — |
| microsoft | skype_for_business_server_2015_cu12 | >= 9319.0 < 9319.628 | 9319.628 |
| microsoft | skype_for_business_server_2019_cu6 | >= 2046.0 < 2046.396 | 2046.396 |
| msrc | skype_for_business_server_2015_cu12 | — | — |
| msrc | skype_for_business_server_2019_cu6 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Skype for Business and Lync Spoofing Vulnerability
vendor_msrc·2022-04-12·CVSS 5.3
CVE-2022-26910 [MEDIUM] Skype for Business and Lync Spoofing Vulnerability
Skype for Business and Lync Spoofing Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An attacker could make a specially crafted network call to the target Skype for Business server, which could cause the parsing of an http request made to an arbitrary address. This could disclose IP addresses or port numbers or both to the attacker.
Skype for Business: Skype for Business
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/download/details.aspx?familyid=0d08ed37-106a-456f-a5c6-61df22588bec
Reference: https://support.microsoft.com/help/5012686
GHSA
GHSA-gq3f-cc5w-p8w5: Skype for Business and Lync Spoofing Vulnerability
ghsa_unreviewed·2022-04-16
CVE-2022-26910 [MEDIUM] CWE-290 GHSA-gq3f-cc5w-p8w5: Skype for Business and Lync Spoofing Vulnerability
Skype for Business and Lync Spoofing Vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-15
Published