Junglewise Threat Intelligence

CVE-2026-66305: Microsoft Skype for Business authentication spoofing

CVE-2026-66305 · Severity: high · CVSS 7.1 · Published 2026-09-08

Technologies: Microsoft Skype for Business. Vendors: Microsoft.

Executive brief

Skype for Business, Microsoft's enterprise messaging and collaboration platform, uses client-side authentication that can be bypassed by authorized network users to impersonate other users. An attacker with network access could falsify the identity of legitimate users when communicating over the network, potentially damaging trust in internal communications and enabling social engineering attacks.

Technical details

The vulnerability exists in Skype for Business's implementation of client-side authentication, which fails to properly validate the origin and integrity of authentication credentials over the network. An authorized attacker with network access can intercept and replay authentication tokens or forge authentication claims to impersonate legitimate users. This is a spoofing vulnerability that requires network access but does not require prior compromise of user credentials. The attack vector is network-based and does not require local system access or user interaction beyond normal network communication.

Affected products

  • Microsoft Skype for Business

Timeline

  • 2026-09-08: disclosed

References

Related threats