← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-0798

A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.

No Active Exploit Signals
CVSS Base Score
6.1
MEDIUM
EPSS Probability:2.08%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
Microsoft Skype for Business Server 2015 March 2019 Update (affected)
Microsoft Microsoft Lync Server 2013 July 2018 Update (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.084%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMicrosoft Corporation · Vendor · USA
Reserved2018-11-26T00:00:00
Published2019-04-09T02:33:50
Patch Date2019-03-12
Last Updated2024-08-04T17:58:59

LINK COPIED TO CLIPBOARD