CVE-2026-63523: Skype for Business Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Other sources
Skype for Business Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.9319.885Patch KB5123301 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.2046.569Patch KB5123300 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.2046.879Patch KB5123287
Event History
Frequently Asked Questions
What does an attacker need to exploit this vulnerability?
The attacker can act remotely over a network and does not need prior privileges. Exploitation requires user interaction.
Which deployments are identified as affected?
The affected software listed is Microsoft Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1.
What is the likely security impact?
The vulnerability is an input-neutralization issue during web page generation, classified as cross-site scripting. Its stated impact is spoofing, and the supplied vector indicates high confidentiality impact with no integrity or availability impact.