Description
Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: 1.1% Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An out‑of‑bounds read in Skype for Business allows a user who has already to the server to force it to stop responding, effectively denying service to all users. The weakness is a classic memory‑traversal bug (CWE‑125).

Affected Systems

The vulnerability affects Microsoft Skype for Business Server 2015 CU13, Microsoft Skype for Business Server 2019 CU8, and Microsoft Skype for Business Server Subscription Edition CU1. These are the only versions identified by the CNA and listed in the vulnerability advisory.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of 0.00612 indicates an extremely low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the vulnerability can be leveraged by an authorized user with access to the server who can send crafted messages over the network; no special privileges beyond authentication are required, suggesting the attack vector is local but network‑bound.

Generated by OpenCVE AI on September 9, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the update available from Microsoft’s Security Update Guide for CVE-2026-66308
  • Restart the Skype for Business server services after applying the patch
  • If patching is delayed, place the affected servers on an isolated network segment and restrict external access to mitigate opportunistic denial of service attempts

Generated by OpenCVE AI on September 9, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft skype For Business Server
CPEs cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13_hotfix_2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix1:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server:2019:cumulative_update_8_hotfix2:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:7.0.2046.849:*:*:*:*:*:*:*
Vendors & Products Microsoft skype For Business Server

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network.
Title Skype for Business and Lync Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
Weaknesses CWE-125
CPEs cpe:2.3:a:microsoft:skype_for_business_server_2015:*:cu13:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_2019:*:cu8:*:*:*:*:*:*
cpe:2.3:a:microsoft:skype_for_business_server_subscription_edition:*:cu1:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft skype For Business Server 2015
Microsoft skype For Business Server 2019
Microsoft skype For Business Server Subscription Edition
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Skype For Business Server Skype For Business Server 2015 Skype For Business Server 2019 Skype For Business Server Subscription Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:30:17.453Z

Reserved: 2026-07-24T18:06:51.295Z

Link: CVE-2026-66308

cve-icon Vulnrichment

Updated: 2026-09-08T20:45:06.643Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T19:18:08.450

Modified: 2026-09-16T19:25:08.633

Link: CVE-2026-66308

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:07Z

Weaknesses