Executive brief
Microsoft Skype for Business Server contains a privilege escalation vulnerability caused by improper handling of server-side requests (SSRF). An unauthenticated attacker can send a specially crafted network request to gain access to sensitive information, such as IP addresses or port numbers, which could lead to further elevation of privilege.
Affected products
- Microsoft Skype for Business Server 2015 Cumulative Update 13
- Microsoft Skype for Business Server 2019 Cumulative Update 7
Timeline
- 2023-10-10: disclosed
- 2023-10-10: advisory
- 2023-10-10: patched
- 2023-10-10: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2023-10-10: exploited: Reported as exploited in the wild at the time of publication.