Executive brief
Microsoft Skype for Business is a unified communications platform used by organizations for messaging, voice, and video calling. A null pointer dereference vulnerability allows authenticated users to crash the application, causing a denial of service and disrupting communications for affected users and teams.
Technical details
A null pointer dereference vulnerability exists in Skype for Business that can be triggered by an authorized/authenticated attacker over the network. The vulnerability occurs when the application attempts to dereference a null pointer without proper validation, leading to an application crash and denial of service. This requires the attacker to have valid authentication credentials to access the service. The specific vulnerable component and triggering conditions are not detailed in the available advisory text, but a patch from Microsoft is expected.
Affected products
- Microsoft Skype for Business
Timeline
- 2026-09-08: disclosed