Executive brief
Skype for Business, a widely-deployed enterprise unified communications platform, contains a cross-site scripting (XSS) vulnerability in web page generation. An attacker can inject malicious scripts that execute in users' browsers, potentially enabling account spoofing, credential theft, or social engineering attacks against employees using the service.
Technical details
The vulnerability is an improper neutralization of input during web page generation (CWE-79 cross-site scripting). User-supplied input is not properly sanitized before being rendered in web pages served by Skype for Business, allowing an attacker to inject arbitrary JavaScript. The attack is network-based and does not require authentication or user interaction beyond visiting a malicious link or page. An attacker can exploit this to perform spoofing, steal session tokens, redirect users to phishing sites, or manipulate displayed content. Microsoft has released a security update to remediate this issue.
Affected products
- Microsoft Skype for Business
Timeline
- 2026-09-08: disclosed