ZeroHour

CVE-2026-66305

large

Client-Side Authentication Spoofing in Skype for Business

CVSS 3.1
7.1 high
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-66305 is a spoofing vulnerability in Skype for Business caused by reliance on client-side authentication (CWE-603), meaning identity checks are enforced on the client rather than fully validated on the server side. An attacker who already holds valid, low-privileged credentials can trigger the flaw over the network without user interaction by manipulating the authentication flow to impersonate another user. Per the CVSS vector, successful spoofing carries a high integrity impact (communications or actions can appear to originate from another user), with low confidentiality impact and no availability impact. Organizations running the Skype for Business deployments identified in Microsoft's advisory are affected; specific affected version ranges are not enumerated in the available data. The flaw is not known to be exploited: there is no public proof of concept, it is absent from CISA's KEV catalog, and EPSS assigns a 0.3% probability of exploitation within 30 days (23rd percentile).

What to do: Check Microsoft's security advisory for this CVE to identify affected Skype for Business versions and apply the corresponding security update. Until patching is complete, restrict network access to Skype for Business services to trusted networks and review external/guest authentication settings, since exploitation requires valid low-privileged credentials. Monitor communications for signs of user impersonation or spoofed identities.

Affected
Microsoft Skype for Business
Estimated exposure
large≈100k–1M users in residual on-premises enterprise deployments (estimate, not a measured count) — Microsoft retired the cloud-based Skype for Business Online in 2021, leaving an install base concentrated in on-premises Skype for Business Server deployments at enterprises and regulated-sector organizations, so this order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.

Weakness
CWE-603
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.