Impact
The vulnerability is a server‑side request forgery in Skype for Business servers that permits an unauthenticated attacker to cause the server to make arbitrary HTTP requests to internal or external resources, leading to disclosure of sensitive information. Because the flaw originates on the server side, the attacker need not have credentials or prior access; this is a typical SSRF scenario identified with CWE‑918. The disclosed data could include internal network details, configuration information, or other content accessible to the server, compromising confidentiality.
Affected Systems
Microsoft has identified the flaw in Skype for Business Server 2015 released with Cumulative Update 13, the 2019 edition released with Cumulative Update 8, and the Subscription Edition released with CU1. All three versions include the affected component and are vulnerable until the Microsoft security update is applied.
Risk and Exploitability
Microsoft lists the vulnerability with a CVSS score of 7.5. The EPSS score is not available, and the issue is not currently in the CISA KEV catalog. Attackers can exploit the SSRF by forging requests to the server; no authentication is required, implying a low barrier to entry from an external or compromised internal host. The risk is therefore moderate to high, especially in environments where the server has broad network reach or where internal resources are exposed to the internet. Prompt remediation is advised.
OpenCVE Enrichment