First published: Tue May 11 2021(Updated: )
Skype for Business and Lync Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Lync Server | =2013-cumulative_update_10 | |
Microsoft Skype For Business Server | =2015-cumulative_update_11 | |
Microsoft Skype For Business Server | =2019-cumulative_update_5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26422 is a remote code execution vulnerability in Skype for Business and Lync Server.
CVE-2021-26422 has a severity score of 7.2, which is considered high.
Microsoft Lync Server 2013 (Cumulative Update 10), Microsoft Skype for Business Server 2015 (Cumulative Update 11), and Microsoft Skype for Business Server 2019 (Cumulative Update 5) are affected by CVE-2021-26422.
Apply the relevant security updates provided by Microsoft to fix CVE-2021-26422.
You can find more information about CVE-2021-26422 on the Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26422