First published: Tue Apr 12 2022(Updated: )
Skype for Business Information Disclosure Vulnerability
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Lync Server | =2013-cumulative_update_10 | |
Microsoft Skype For Business Server | =2015-cu12 | |
Microsoft Skype For Business Server | =2019-cu6 | |
Microsoft Lync Server 2013 CU10 | ||
Microsoft Skype for Business Server 2019 CU6 | ||
Microsoft Skype for Business Server 2015 CU12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-26911 is high with a severity value of 6.5.
Skype for Business Server 2015 CU12, Skype for Business Server 2019 CU6, and Lync Server 2013 CU10 are affected by CVE-2022-26911.
Apply the appropriate patches or updates provided by Microsoft. For Lync Server 2013 CU10, use the patch available at https://www.microsoft.com/downloads/details.aspx?familyid=dac7c777-fe8a-45a2-9a82-07a2e15c298f. For Skype for Business Server 2015 CU12 and Skype for Business Server 2019 CU6, use the patch available at https://www.microsoft.com/downloads/details.aspx?familyid=0d08ed37-106a-456f-a5c6-61df22588bec.
You can find more information about CVE-2022-26911 at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26911.