Executive brief
Skype for Business contains an out-of-bounds read vulnerability that allows an authorized attacker to cause a denial of service condition. An attacker with valid credentials can trigger a network-based attack that crashes the application or makes it unavailable to users.
Technical details
An out-of-bounds read vulnerability exists in Microsoft Skype for Business, allowing an authenticated attacker to trigger a denial of service condition. The vulnerability requires network access and valid authentication credentials. By sending a specially crafted network message, an attacker can cause the application to read memory outside of allocated bounds, leading to application crash or service interruption. A patch is available from Microsoft.
Affected products
- Microsoft Skype for Business
Timeline
- 2026-09-08: disclosed: CVE-2026-66308 published