Impact
An integer underflow (wrap or wraparound) in Microsoft Skype for Business allows an unauthorized user to cause a denial of service via a network interaction. The flaw is a classic CWE‑191 condition that can cause the application to misbehave and become unreachable for legitimate users.
Affected Systems
The vulnerability is present in Microsoft Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact on availability, while the EPSS score is not available and the issue is not currently listed in CISA’s KEV catalog, suggesting limited known exploitation. The likely attack vector is remote over the network, inferred from the description that an attacker can trigger the underflow via network traffic to the affected services.
OpenCVE Enrichment