Description
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: 1.1% Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A null pointer dereference flaw in Microsoft Skype for Business Server allows an attacker who is already authenticated to a network to cause a denial of service condition. The vulnerability is classified as CWE‑476 and results in the application crashing or becoming non‑responsive for authenticated users. Because the function or resource that is being dereferenced is accessed with insufficient validation, the server cannot recover and all operations that depend on that component will fail until the service is restarted.

Affected Systems

The flaw affects Microsoft Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1. These are the server editions that provide internal voice, video and collaboration services within an enterprise network.

Risk and Exploitability

The CVSS score of 6.5 denotes a moderate to high severity. EPSS data is not available, so current publicly observed exploitation risk is unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have valid credentials to the Skype for Business environment, which reduces the attack surface relative to a purely unauthenticated flaw. Nonetheless, a successful exploit would interrupt communications for all affected users until the service is restored, potentially impacting business operations.

Generated by OpenCVE AI on September 9, 2026 at 13:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update that addresses CVE-2026-66303 for the appropriate Skype for Business Server release (CU13 for 2015, CU8 for 2019, or CU1 for Subscription Edition).
  • Limit the use of privileged or service accounts that connect to Skype for Business, ensuring that only necessary users have the ability to log into the server.
  • Monitor application logs for unexpected crashes or service restarts after applying the update to verify that the denial of service condition is no longer triggered.

Generated by OpenCVE AI on September 9, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft skype For Business Server
CPEs cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
Vendors & Products Microsoft skype For Business Server

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
Title Skype for Business and Lync Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
Weaknesses CWE-476
CPEs cpe:2.3:a:microsoft:skype_for_business_server_2015:*:cu13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_2019:*:cu8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:*:cu1:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Skype For Business Server Skype For Business Server 2015 Skype For Business Server 2019 Skype For Business Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:39:19.952Z

Reserved: 2026-07-24T18:06:51.294Z

Link: CVE-2026-66303

cve-icon Vulnrichment

Updated: 2026-09-08T20:44:50.703Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:07.820

Modified: 2026-09-16T19:23:02.977

Link: CVE-2026-66303

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:07Z

Weaknesses