Описание
Skype for Business Remote Code Execution Vulnerability
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An unauthenticated attacker could exploit this vulnerability over the network by sending a specially crafted request that writes an attacker-controlled file to an arbitrary location on the affected server. Successful exploitation could result in the attacker executing code on the target server. No authentication or user interaction is required.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Skype for Business Server 2015 CU13 | - | |
| Skype for Business Server 2019 CU8 | - | |
| Skype for Business Server Subscription Edition CU1 |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.
Уязвимость программы мгновенного обмена сообщениями Skype for Business Server, связанная с некорректным внешним управлением именем или путем файла, позволяющая нарушителю выполнить произвольный код
EPSS
9.8 Critical
CVSS3