Executive brief
Skype for Business, a unified communications platform used by enterprises for instant messaging and video conferencing, contains a flaw in cryptographic signature verification. An attacker on an adjacent network could forge communication signatures and impersonate legitimate users or services, potentially leading to unauthorized access, credential theft, or disruption of business communications.
Technical details
The vulnerability is an improper cryptographic signature verification issue in Skype for Business that allows signature spoofing attacks. An attacker positioned on an adjacent network (not requiring internet routing) can forge valid-appearing signatures to impersonate other users or services. The attack requires network adjacency but does not appear to require prior authentication or user interaction. Successful exploitation could allow an attacker to spoof communications, potentially leading to social engineering, credential harvesting, or unauthorized access to sensitive conversations. A patch from Microsoft is expected to be available.
Affected products
- Microsoft Skype for Business
Timeline
- 2026-09-08: disclosed