CVE-2022-26910: Skype for Business and Lync Spoofing Vulnerability
Published Apr 12, 2022
·Updated
Skype for Business and Lync Spoofing Vulnerability
Affected Software
4 affected componentsFixes available
Microsoft Skype for Business Server 2019 CU6
Microsoft Skype for Business Server 2015 CU12
Microsoft Skype for Business Server=2015-cu12
Microsoft Skype for Business Server=2019-cu6
Event History
Apr 12, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Apr 15, 2022
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-26910?
CVE-2022-26910 is a Skype for Business and Lync Spoofing Vulnerability that allows an attacker to spoof an authenticated user's identity.
2
Which software versions are affected by CVE-2022-26910?
Microsoft Skype for Business Server 2015 CU12 and Microsoft Skype for Business Server 2019 CU6 are affected by CVE-2022-26910.
3
What is the severity rating of CVE-2022-26910?
CVE-2022-26910 has a severity rating of 5.3 (High).
4
How can I fix CVE-2022-26910?
To fix CVE-2022-26910, update your Microsoft Skype for Business Server to the recommended versions: 2015 CU12 or 2019 CU6.
5
Where can I find more information about CVE-2022-26910?
You can find more information about CVE-2022-26910 on the Microsoft Security Response Center website.