Junglewise Threat Intelligence

CVE-2023-41763: Microsoft Skype for Business Privilege Escalation Vulnerability

CVE-2023-41763 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2023-10-10

Technologies: Microsoft Skype for Business. Vendors: Microsoft.

Executive brief

Microsoft Skype for Business Server contains a privilege escalation vulnerability caused by improper handling of server-side requests (SSRF). An unauthenticated attacker can send a specially crafted network request to gain access to sensitive information, such as IP addresses or port numbers, which could lead to further elevation of privilege.

Affected products

  • Microsoft Skype for Business Server 2015 Cumulative Update 13
  • Microsoft Skype for Business Server 2019 Cumulative Update 7

Timeline

  • 2023-10-10: disclosed
  • 2023-10-10: advisory
  • 2023-10-10: patched
  • 2023-10-10: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2023-10-10: exploited: Reported as exploited in the wild at the time of publication.

Related threats