CVE-2022-33633: Skype for Business and Lync Remote Code Execution Vulnerability
Published Jul 12, 2022
·Updated
Skype for Business and Lync Remote Code Execution Vulnerability
Affected Software
6 affected componentsFixes available
Microsoft Skype for Business Server 2019 CU6
Microsoft Skype for Business Server 2015 CU12
Microsoft Lync Server 2013 CU10
Microsoft Lync Server=2013-cumulative_update_10
Microsoft Skype for Business=2015-cumulative_update_12
Microsoft Skype for Business=2019-cumulative_update_6
Event History
Jul 12, 2022
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·10:37 PM
Data Sourced
via MITRE·10:37 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-33633?
CVE-2022-33633 refers to the Skype for Business and Lync Remote Code Execution Vulnerability.
2
How does CVE-2022-33633 affect Skype for Business and Lync?
CVE-2022-33633 allows remote attackers to execute arbitrary code or cause a denial of service on Skype for Business and Lync servers.
3
What is the severity of CVE-2022-33633?
CVE-2022-33633 has a severity rating of high.
4
Which versions of Skype for Business and Lync are affected by CVE-2022-33633?
Skype for Business Server 2015 CU12, Skype for Business Server 2019 CU6, and Lync Server 2013 CU10 are affected by CVE-2022-33633.
5
How can I fix CVE-2022-33633?
To fix CVE-2022-33633, apply the respective cumulative updates provided by Microsoft for the affected versions of Skype for Business and Lync.