Impact
An error message generated by Skype for Business Server may contain sensitive information. An attacker without authorization can obtain this data by observing the error message sent over the network, leading to potential compromise of confidential details. The vulnerability emerges from the way error output is constructed, revealing sensitive data. The impacted weakness is categorized as CWE-209.
Affected Systems
The flaw affects Microsoft Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1. These versions are specifically listed as vulnerable in the Microsoft advisory. No other editions or versions are indicated.
Risk and Exploitability
The CVSS rating is 6.5, indicating a medium severity. Since the exploit occurs by intercepting error messages over the network, the attack vector is likely remote, requiring network access to the server. EPSS data is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog. Recovering from exploitation would allow the attacker to read sensitive information, potentially undermining confidentiality.
OpenCVE Enrichment