Impact
This vulnerability arises from uncontrolled file name or path input in Skype for Business, allowing an attacker to instruct the server to execute arbitrary code at a remote endpoint. The weakness, identified as CWE-73, could enable adversaries to compromise confidentiality, integrity, and availability of the affected server by executing malicious payloads with the same privileges as the Skype service.
Affected Systems
The affected products are Microsoft Skype for Business Server 2015 CU13, Microsoft Skype for Business Server 2019 CU8, and Microsoft Skype for Business Server Subscription Edition CU1. Only these specific update channel versions are known to be vulnerable; later CUs may not suffer from the flaw.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical risk level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the description implies a network‑based exploitation path and the potential for remote code execution. The likely attack vector is over a network where an unauthenticated or minimally privileged attacker can send crafted file name or path values to the server, triggering malicious code execution.
OpenCVE Enrichment