CVE-2019-1490: Medium severity microsoft skype for business vulnerability
Published Dec 10, 2019
·Updated
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Server Spoofing Vulnerability'.
Affected Software
1 affected component
Microsoft Skype for Business=2019-cumulative_update_2
Remediation
Event History
Dec 10, 2019
CVE Published
via MITRE·09:41 PM
Data Sourced
via MITRE·09:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-1490?
CVE-2019-1490 is a spoofing vulnerability that exists in Skype for Business Server.
2
How does the CVE-2019-1490 vulnerability occur?
The vulnerability occurs when a Skype for Business Server does not properly sanitize a specially crafted request.
3
What is the severity of CVE-2019-1490?
The severity of CVE-2019-1490 is medium (5.4).
4
Which version of Microsoft Skype for Business is affected by CVE-2019-1490?
Microsoft Skype for Business 2019 Cumulative Update 2 is affected by CVE-2019-1490.
5
How can I fix CVE-2019-1490?
To fix CVE-2019-1490, apply the necessary security updates provided by Microsoft.