CVE-2021-26422: Skype for Business and Lync Remote Code Execution Vulnerability
Published May 11, 2021
·Updated
Skype for Business and Lync Remote Code Execution Vulnerability
Affected Software
3 affected components
Microsoft Lync Server=2013-cumulative_update_10
Microsoft Skype for Business Server=2015-cumulative_update_11
Microsoft Skype for Business Server=2019-cumulative_update_5
Remediation
Event History
May 11, 2021
CVE Published
07:11 PM
Data Sourced
07:11 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2021-26422?
CVE-2021-26422 is a remote code execution vulnerability in Skype for Business and Lync Server.
2
How severe is CVE-2021-26422?
CVE-2021-26422 has a severity score of 7.2, which is considered high.
3
Which software versions are affected by CVE-2021-26422?
Microsoft Lync Server 2013 (Cumulative Update 10), Microsoft Skype for Business Server 2015 (Cumulative Update 11), and Microsoft Skype for Business Server 2019 (Cumulative Update 5) are affected by CVE-2021-26422.
4
How can I fix CVE-2021-26422?
Apply the relevant security updates provided by Microsoft to fix CVE-2021-26422.
5
Where can I find more information about CVE-2021-26422?
You can find more information about CVE-2021-26422 on the Microsoft Security Guidance Advisory page: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-26422