Skype for Business Elevation of Privilege Vulnerability
CVE-2023-41763
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 10 October 2023
Badges
Summary
Skype for Business Elevation of Privilege Vulnerability
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Skype for Business Server 2015 CU13 Unknown 9319.0 < 6.0.9319.869
Skype for Business Server 2019 CU7 Unknown 2046.0 < 7.0.246.530
News Articles
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- π°
First article discovered by The Record from Recorded Future News
- πΎ
Exploit known to exist
- π¦
CISA Reported
Vulnerability published
Vulnerability Reserved