Impact
An out‑of‑bounds read in Skype for Business allows a user who has already to the server to force it to stop responding, effectively denying service to all users. The weakness is a classic memory‑traversal bug (CWE‑125).
Affected Systems
The vulnerability affects Microsoft Skype for Business Server 2015 CU13, Microsoft Skype for Business Server 2019 CU8, and Microsoft Skype for Business Server Subscription Edition CU1. These are the only versions identified by the CNA and listed in the vulnerability advisory.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of 0.00612 indicates an extremely low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the vulnerability can be leveraged by an authorized user with access to the server who can send crafted messages over the network; no special privileges beyond authentication are required, suggesting the attack vector is local but network‑bound.
OpenCVE Enrichment