Description
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

An error message generated by Skype for Business Server may contain sensitive information. An attacker without authorization can obtain this data by observing the error message sent over the network, leading to potential compromise of confidential details. The vulnerability emerges from the way error output is constructed, revealing sensitive data. The impacted weakness is categorized as CWE-209.

Affected Systems

The flaw affects Microsoft Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1. These versions are specifically listed as vulnerable in the Microsoft advisory. No other editions or versions are indicated.

Risk and Exploitability

The CVSS rating is 6.5, indicating a medium severity. Since the exploit occurs by intercepting error messages over the network, the attack vector is likely remote, requiring network access to the server. EPSS data is unavailable, and the vulnerability is not currently listed in the CISA KEV catalog. Recovering from exploitation would allow the attacker to read sensitive information, potentially undermining confidentiality.

Generated by OpenCVE AI on September 9, 2026 at 14:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update for Skype for Business Server 2015 CU13, 2019 CU8, and Subscription Edition CU1 as detailed in the MSRC update guide.
  • Configure the server to suppress or mask sensitive data in error messages, ensuring that no confidential information is exposed in logs or network traffic.
  • Monitor network traffic for unintended disclosure of error messages and disable any debugging or verbose logging that may reveal sensitive data.

Generated by OpenCVE AI on September 9, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft skype For Business Server
CPEs cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
Vendors & Products Microsoft skype For Business Server

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
Title Skype for Business Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
Weaknesses CWE-209
CPEs cpe:2.3:a:microsoft:skype_for_business_server_2015:*:cu13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_2019:*:cu8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:*:cu1:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Skype For Business Server Skype For Business Server 2015 Skype For Business Server 2019 Skype For Business Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:16.310Z

Reserved: 2026-07-24T18:06:51.294Z

Link: CVE-2026-66306

cve-icon Vulnrichment

Updated: 2026-09-08T18:52:57.126Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:08.200

Modified: 2026-09-16T19:24:24.507

Link: CVE-2026-66306

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:07Z

Weaknesses
  • CWE-209

    Generation of Error Message Containing Sensitive Information