Executive brief
Skype for Business, a widely-used enterprise communication platform, contains a server-side request forgery vulnerability that allows an unauthorized attacker to make unauthorized requests from the affected server. An attacker exploiting this flaw could access internal resources or services that should not be publicly reachable, potentially exposing sensitive business communications and data.
Technical details
A server-side request forgery (SSRF) vulnerability exists in Skype for Business, allowing an attacker to make arbitrary HTTP requests from the affected server. The vulnerability is network-accessible and does not require authentication, enabling an unauthorized attacker to disclose information by forcing the server to request internal or restricted resources. An attacker can leverage this to access backend services, internal APIs, or sensitive data that would normally be restricted from external access. This flaw permits information disclosure over the network without user interaction.
Affected products
- Microsoft Skype for Business
Timeline
- 2026-09-08: disclosed