ZeroHour

CVE-2026-66307

large

Unauthenticated Integer Underflow DoS in Microsoft Skype for Business

CVSS 3.1
7.5 high
EPSS
<1%p49
Published
()
Modified
AI analysis

CVE-2026-66307 is an integer underflow (CWE-191) in Microsoft Skype for Business: when the software processes attacker-supplied network traffic, a length or count calculation can wrap around below zero, allowing an unauthenticated remote attacker to disrupt the affected service. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) scores 7.5 High and confirms the impact is denial of service only, with no confidentiality or integrity loss. The data names only "Skype for Business" without version ranges; given that Microsoft-hosted Skype for Business Online was retired in 2021, the affected customer-patchable product is most plausibly the on-premises Skype for Business Server, and only deployments with network-reachable service interfaces are exposed. There is no public proof of concept, the issue is not in CISA KEV, and EPSS estimates only about a 0.6% chance of exploitation within 30 days (49th percentile), so no exploitation is currently known.

What to do: Apply Microsoft's security update for CVE-2026-66307; because this data does not include affected version ranges, verify the exact versions and update paths in Microsoft's advisory before patching. Until patched, restrict network access to Skype for Business server services (especially externally exposed interfaces) to trusted clients via firewall rules or VPN. Re-check CISA KEV and EPSS over the coming weeks for signs of rising exploitation, since no exploitation is known today.

Affected
Microsoft Skype for Business
Estimated exposure
largeorder of 10,000 to 100,000 on-premises Skype for Business deployments worldwide (rough estimate) — Microsoft publishes no install counts for Skype for Business Server, but the product remains a widely deployed legacy enterprise unified-communications platform, and only externally reachable service interfaces can be attacked remotely, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.

Weakness
CWE-191
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.