CVE-2026-66307
largeUnauthenticated Integer Underflow DoS in Microsoft Skype for Business
CVE-2026-66307 is an integer underflow (CWE-191) in Microsoft Skype for Business: when the software processes attacker-supplied network traffic, a length or count calculation can wrap around below zero, allowing an unauthenticated remote attacker to disrupt the affected service. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) scores 7.5 High and confirms the impact is denial of service only, with no confidentiality or integrity loss. The data names only "Skype for Business" without version ranges; given that Microsoft-hosted Skype for Business Online was retired in 2021, the affected customer-patchable product is most plausibly the on-premises Skype for Business Server, and only deployments with network-reachable service interfaces are exposed. There is no public proof of concept, the issue is not in CISA KEV, and EPSS estimates only about a 0.6% chance of exploitation within 30 days (49th percentile), so no exploitation is currently known.
What to do: Apply Microsoft's security update for CVE-2026-66307; because this data does not include affected version ranges, verify the exact versions and update paths in Microsoft's advisory before patching. Until patched, restrict network access to Skype for Business server services (especially externally exposed interfaces) to trusted clients via firewall rules or VPN. Re-check CISA KEV and EPSS over the coming weeks for signs of rising exploitation, since no exploitation is known today.
| Microsoft Skype for Business | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.
- Weakness
- CWE-191
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.