Impact
Improper verification of cryptographic signatures in Microsoft Skype for Business Server allows an unauthorized attacker to impersonate legitimate users or devices over an adjacent network. The flaw enables the attacker to send traffic that the server will accept as authenticated, potentially leading to unauthorized access to resources or data. The impact is primarily the ability to spoof identity within the Skype for Business environment, which could be leveraged for further attacks such as eavesdropping or credential theft.
Affected Systems
The vulnerability affects Microsoft Skype for Business Server 2015 CU13, Microsoft Skype for Business Server 2019 CU8, and Microsoft Skype for Business Server Subscription Edition CU1. No additional version details are provided beyond the specified cumulative update levels.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is also not listed in the CISA KEV catalog. The likely attack vector is an attacker present on a network adjacent to the affected server who can send forged authentication traffic that bypasses proper signature verification. Without a patch, the server is susceptible to identity spoofing and related compromise risks.
OpenCVE Enrichment