Description
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
Published: 2026-09-08
Score: 7.5 High
EPSS: 1.2% Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An integer underflow (wrap or wraparound) in Microsoft Skype for Business allows an unauthorized user to cause a denial of service via a network interaction. The flaw is a classic CWE‑191 condition that can cause the application to misbehave and become unreachable for legitimate users.

Affected Systems

The vulnerability is present in Microsoft Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact on availability, while the EPSS score is not available and the issue is not currently listed in CISA’s KEV catalog, suggesting limited known exploitation. The likely attack vector is remote over the network, inferred from the description that an attacker can trigger the underflow via network traffic to the affected services.

Generated by OpenCVE AI on September 9, 2026 at 13:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft security update for the affected Skype for Business Server versions as published in the MSRC advisory.
  • Block external access to the Skype for Business Server transport ports (e.g., 5060/5061, 443) using firewall or network segmentation until the patch is fully deployed.
  • After patch deployment, verify that service availability and functionality return to normal and monitor for repeated denial of service patterns; keep the server updated with future patches.

Generated by OpenCVE AI on September 9, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft skype For Business Server
CPEs cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
Vendors & Products Microsoft skype For Business Server

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
Title Skype for Business and Lync Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
Weaknesses CWE-191
CPEs cpe:2.3:a:microsoft:skype_for_business_server_2015:*:cu13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_2019:*:cu8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:*:cu1:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Skype For Business Server Skype For Business Server 2015 Skype For Business Server 2019 Skype For Business Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:39:20.538Z

Reserved: 2026-07-24T18:06:51.294Z

Link: CVE-2026-66307

cve-icon Vulnrichment

Updated: 2026-09-08T19:17:09.539Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:08.327

Modified: 2026-09-16T19:24:44.230

Link: CVE-2026-66307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T23:00:05Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)