CVE-2022-33633
published 2022-07-12CVE-2022-33633: Skype for Business and Lync Remote Code Execution Vulnerability
PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.20%
80.5th percentile
Skype for Business and Lync Remote Code Execution Vulnerability
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | lync_server | — | — |
| microsoft | microsoft_lync_server_2013_cu10 | >= 8308.0 < 8308.1198 | 8308.1198 |
| microsoft | skype_for_business | — | — |
| microsoft | skype_for_business | — | — |
| microsoft | skype_for_business_server_2015_cu12 | >= 9319.0 < 9319.634 | 9319.634 |
| microsoft | skype_for_business_server_2019_cu6 | >= 2046.0 < 2046.404 | 2046.404 |
| msrc | microsoft_lync_server_2013_cu10 | — | — |
| msrc | skype_for_business_server_2015_cu12 | — | — |
| msrc | skype_for_business_server_2019_cu6 | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m4g8-6pfp-59jr: Skype for Business and Lync Remote Code Execution Vulnerability
ghsa_unreviewed·2022-07-13
CVE-2022-33633 [HIGH] GHSA-m4g8-6pfp-59jr: Skype for Business and Lync Remote Code Execution Vulnerability
Skype for Business and Lync Remote Code Execution Vulnerability.
Microsoft
Skype for Business and Lync Remote Code Execution Vulnerability
vendor_msrc·2022-07-12·CVSS 7.2
CVE-2022-33633 [HIGH] Skype for Business and Lync Remote Code Execution Vulnerability
Skype for Business and Lync Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, privileges required is high (PR:H). What privileges are needed by the attacker and how are they used in the context of the remote code execution?
To successfully exploit this vulnerability, the attacker must have write access on the file share, and an active file share administrator account on the target
server. With write access, the attacker would need to modify specific files on the target server to trigger code execution.
Skype for Business and Microsoft Lync: Skype for Business and Microsoft Lync
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older S
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-07-12
Published