Microsoft Skype For Business vulnerabilities
32 known vulnerabilities affecting microsoft/skype_for_business.
Total CVEs
32
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH14MEDIUM11LOW1
Vulnerabilities
Page 2 of 2
CVE-2016-3262P3MEDIUMCVSS 5.5v20162016-10-14
CVE-2016-3262 [MEDIUM] CWE-200 CVE-2016-3262: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeti
nvd
CVE-2016-3263P3MEDIUMCVSS 5.5v20162016-10-14
CVE-2016-3263 [MEDIUM] CVE-2016-3263: Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007
nvd
CVE-2024-20673P3HIGHCVSS 7.8v20162024-02-13
CVE-2024-20673 [HIGH] CWE-693 CVE-2024-20673: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2018-8238P3HIGHCVSS 7.8v20162018-07-11
CVE-2018-8238 [HIGH] CVE-2018-8238: A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse
A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync.
nvd
CVE-2019-1084P3MEDIUMCVSS 6.5v2016v2016 (32-bit)+1 more2019-07-15
CVE-2019-1084 [MEDIUM] CWE-200 CVE-2019-1084: An information disclosure vulnerability exists when Exchange allows creation of entities with Displa
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by valida
nvd
CVE-2017-0073P4MEDIUMCVSS 4.3v20162017-03-17
CVE-2017-0073 [MEDIUM] CVE-2017-0073: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows GDI+ Information Disclosure Vul
nvd
CVE-2017-8695P3MEDIUMCVSS 5.3v20162017-09-13
CVE-2017-8695 [MEDIUM] CWE-200 CVE-2017-8695: Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windo
Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live
nvd
CVE-2018-8546P4MEDIUMCVSS 5.9v20162018-11-14
CVE-2018-8546 [MEDIUM] CVE-2018-8546: A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business De
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.
nvd
CVE-2019-1490P4MEDIUMCVSS 5.4v20192019-12-10
CVE-2019-1490 [MEDIUM] CWE-74 CVE-2019-1490: A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specia
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'.
nvd
CVE-2015-6061P4MEDIUMCVSS 4.3v20162015-11-11
CVE-2015-6061 [MEDIUM] CWE-79 CVE-2015-6061: Cross-site scripting (XSS) vulnerability in Microsoft Skype for Business 2016, Lync 2010 and 2013 SP
Cross-site scripting (XSS) vulnerability in Microsoft Skype for Business 2016, Lync 2010 and 2013 SP1, Lync 2010 Attendee, and Lync Room System allows remote attackers to inject arbitrary web script or HTML via an instant-message session, aka "Server Input Validation Information Disclosure Vulnerability."
nvd
CVE-2019-0624P4MEDIUMCVSS 5.4v20152019-01-17
CVE-2019-0624 [MEDIUM] CWE-79 CVE-2019-0624: A spoofing vulnerability exists when a Skype for Business 2015 server does not properly sanitize a s
A spoofing vulnerability exists when a Skype for Business 2015 server does not properly sanitize a specially crafted request, aka "Skype for Business 2015 Spoofing Vulnerability." This affects Skype.
nvd
CVE-2017-8676P4LOWCVSS 3.3v20162017-09-13
CVE-2017-8676 [LOW] CWE-200 CVE-2017-8676: The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows
The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2
nvd
← Previous2 / 2