PT-2022-2902 · Microsoft · Skype For Business Server+1

Rskvp93

·

Published

2022-04-12

·

Updated

2023-06-29

·

CVE-2022-26911

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Skype for Business Server (affected versions not specified)
Description The vulnerability is related to a lack of protection for service data in Skype for Business Server, which can allow a remote attacker to gain unauthorized access to protected information. There have been reports of an Arbitrary File Read vulnerability for internal sites of Skype for Business and MS Lync, affecting subdomains such as dialin, meet, lyncdiscover, and sip.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-03489
CVE-2022-26911

Affected Products

Ms Lync
Skype For Business Server