Junglewise Threat Intelligence

CVE-2026-66307: Microsoft Skype for Business integer underflow denial of service

CVE-2026-66307 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Microsoft Skype for Business. Vendors: Microsoft.

Executive brief

Skype for Business, a widely-deployed enterprise communication platform, contains an integer underflow vulnerability that allows an attacker on the network to cause the service to crash or become unavailable. This vulnerability requires no user interaction or authentication, making it straightforward to exploit and potentially affecting an organization's communication capabilities.

Technical details

An integer underflow (wrap or wraparound) vulnerability exists in Skype for Business that allows an unauthenticated attacker to send specially crafted network packets to trigger a denial of service condition. The vulnerability is remotely exploitable over the network without requiring authentication or user interaction. Successful exploitation causes service disruption, preventing users from accessing Skype for Business functionality. The attack vector is network-based, making it a significant concern for internet-facing deployments or those within corporate networks.

Affected products

  • Microsoft Skype for Business

Timeline

  • 2026-09-08: disclosed

References

Related threats