Security
Headlines
HeadlinesLatestCVEs

Tag

#Skype for Business and Microsoft Lync

CVE-2022-33633: Skype for Business and Lync Remote Code Execution Vulnerability

**According to the CVSS metric, the privileges required is high (PR:H). What privileges are needed by the attacker and how are they used in the context of the remote code execution?** To successfully exploit this vulnerability, the attacker must have write access on the file share, and an active file share administrator account on the target server. With write access, the attacker would need to modify specific files on the target server to trigger code execution.

Microsoft Security Response Center
#vulnerability#web#rce#Skype for Business and Microsoft Lync#Security Vulnerability