ZeroHour

CVE-2023-41763

KEVmass1

Unauthenticated SSRF/Elevation-of-Privilege Flaw in Microsoft Skype for Business Server

CISA: Microsoft Skype for Business Privilege Escalation Vulnerability

CVSS 3.1
5.3 medium
EPSS
90%p100
Published
()
KEV added
AI analysis

CVE-2023-41763 is a vulnerability in Microsoft Skype for Business Server that Microsoft classifies as an elevation-of-privilege issue, with the underlying weakness mapped to CWE-918 (server-side request forgery). The CVSS vector (AV:N/AC:L/PR:N/UI:N, scope unchanged) shows it can be triggered remotely by an unauthenticated attacker sending crafted network requests, and the impact is confined to confidentiality, meaning an attacker can potentially obtain limited sensitive information from the affected server. Any organization running on-premises Skype for Business Server is potentially affected; the source data does not specify the affected version ranges. The flaw was patched in Microsoft's October 2023 Patch Tuesday, where it was fixed alongside the actively exploited WordPad zero-day (CVE-2023-36563), and it was added to CISA's Known Exploited Vulnerabilities catalog on October 10, 2023, carrying a 90.4% EPSS probability of exploitation within 30 days.

What to do: Apply Microsoft's October 2023 Patch Tuesday security updates for Skype for Business Server immediately; CISA's KEV required action is to apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. No public proof-of-concept is known, but exploitation is confirmed in the wild, so prioritize internet-facing deployments and review Skype for Business web-service logs for anomalous requests. Check which Skype for Business Server versions your organization runs against Microsoft's advisory to confirm patch applicability.

Affected
Microsoft Skype for Business Server
Estimated exposure
massplausibly >1 million users across tens of thousands of on-premises server deployments (estimate) — Skype for Business (formerly Lync) Server is a long-established enterprise platform whose user base Microsoft historically reported at over 100 million, and while many customers have migrated to Teams, the remaining on-premises installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Skype for Business Elevation of Privilege Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Skype for Business
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
skype for business server
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news