CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microsoft

skype_for_business

9 known vulnerabilities · sorted by CVSS score

CVE-2020-1025
CRITICAL9.8

An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.

microsoft / lync+5
Network
Published Jul 14, 2020
CVE-2018-8311
HIGH8.8

A remote code execution vulnerability exists when Skype for Business and Microsoft Lync clients fail to properly sanitize specially crafted content, aka "Remote Code Execution Vulnerability in Skype For Business and Lync." This affects Skype, Microsoft Lync.

microsoft / lync+1
Network
Published Jul 11, 2018
CVE-2024-20673
HIGH7.8

Microsoft Office Remote Code Execution Vulnerability

microsoft / excel+8
Local
Published Feb 13, 2024
CVE-2018-8238
HIGH7.8

A security feature bypass vulnerability exists when Skype for Business or Lync do not properly parse UNC path links shared via messages, aka "Skype for Business and Lync Security Feature Bypass Vulnerability." This affects Skype, Microsoft Lync.

microsoft / lync+1
Local
Published Jul 11, 2018
CVE-2022-33633
HIGH7.2

Skype for Business and Lync Remote Code Execution Vulnerability

microsoft / lync_server+2
Network
Published Jul 12, 2022
CVE-2019-1084
MEDIUM6.5

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.

microsoft / exchange_server+21
Network
Published Jul 15, 2019
CVE-2018-8546
MEDIUM5.9

A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.

microsoft / lync+5
Network
Published Nov 14, 2018
CVE-2019-0624
MEDIUM5.4

A spoofing vulnerability exists when a Skype for Business 2015 server does not properly sanitize a specially crafted request, aka "Skype for Business 2015 Spoofing Vulnerability." This affects Skype.

microsoft / skype_for_business
Network
Published Jan 17, 2019
CVE-2019-1490
MEDIUM5.4

A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'.

microsoft / skype_for_business
Network
Published Dec 10, 2019