Impact
A null pointer dereference flaw in Microsoft Skype for Business Server allows an attacker who is already authenticated to a network to cause a denial of service condition. The vulnerability is classified as CWE‑476 and results in the application crashing or becoming non‑responsive for authenticated users. Because the function or resource that is being dereferenced is accessed with insufficient validation, the server cannot recover and all operations that depend on that component will fail until the service is restarted.
Affected Systems
The flaw affects Microsoft Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1. These are the server editions that provide internal voice, video and collaboration services within an enterprise network.
Risk and Exploitability
The CVSS score of 6.5 denotes a moderate to high severity. EPSS data is not available, so current publicly observed exploitation risk is unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have valid credentials to the Skype for Business environment, which reduces the attack surface relative to a purely unauthenticated flaw. Nonetheless, a successful exploit would interrupt communications for all affected users until the service is restored, potentially impacting business operations.
OpenCVE Enrichment