Known vulnerabilities in Skype for Business Server

Vendor: Microsoft
Software CPE: cpe:2.3:a:microsoft:skype_for_business_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 15
Public exploits: 0
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Skype for Business Server Skype for Business Server is affected by 15 known vulnerabilities: 1 high, 4 medium, 10 low Critical High Medium Low

Vulnerabilities (15)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU86440 - Exposure of sensitive information to an unauthorized actor
CVE-2024-20695
CWE-200 Low
No
No
- 13.02.2024 SB2024021362
#VU81806 - Improper input validation
CVE-2023-36780
CWE-20 Low
No
No
6.0.9319.869, 7.0.246.530 10.10.2023 SB2023101085
#VU81805 - Improper input validation
CVE-2023-36789
CWE-20 Low
No
No
6.0.9319.869, 7.0.246.530 10.10.2023 SB2023101085
#VU81804 - Improper input validation
CVE-2023-36786
CWE-20 Low
No
No
6.0.9319.869, 7.0.246.530 10.10.2023 SB2023101085
#VU81729 - Exposure of sensitive information to an unauthorized actor
CVE-2023-41763
CWE-200 High
No
Exploited
6.0.9319.869, 7.0.246.530 10.10.2023 SB2023101033
#VU65212 - Improper input validation
CVE-2022-33633
CWE-20 Low
No
No
- 12.07.2022 SB2022071257
#VU62279 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-26910
CWE-451 Medium
No
No
- 13.04.2022 SB2022041311
#VU62256 - Exposure of sensitive information to an unauthorized actor
CVE-2022-26911
CWE-200 Medium
No
No
- 12.04.2022 SB2022041260
#VU53103 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-26421
CWE-451 Medium
No
No
- 11.05.2021 SB2021051122
#VU53102 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-26422
CWE-94 Low
No
No
- 11.05.2021 SB2021051122
#VU50487 - Improper input validation
CVE-2021-24099
CWE-20 Medium
No
No
- 09.02.2021 SB2021020944
#VU50486 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-24073
CWE-451 Low
No
No
- 09.02.2021 SB2021020944
#VU29729 - Memory corruption
CVE-2020-1025
CWE-119 Low
No
No
- 14.07.2020 SB2020071415
#VU23471 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2019-1490
CWE-451 Low
No
No
- 10.12.2019 SB2019121010
#VU17014 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-0624
CWE-79 Low
No
No
- 15.01.2019 SB2019011604