Input validation error in Lync Server and Skype for Business Server - CVE-2022-33633
Published: July 12, 2022
Vulnerability identifier: #VU65212
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-33633
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input in Skype for Business and Lync. A remote administrator can pass specially crafted input to the application and execute arbitrary code on the target system.
Affected software
Lync Server
Skype for Business Server
Skype for Business Server
How to mitigate CVE-2022-33633
Install updates from vendor's website.