CVE-2026-66303: Skype for Business and Lync Denial of Service Vulnerability
Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.
Other sources
Skype for Business and Lync Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.2046.879Patch KB5123287 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.9319.885Patch KB5123301 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.2046.569Patch KB5123300
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized and able to reach the affected Skype for Business or Lync service over the network. The provided data does not indicate that unauthenticated attackers can exploit it.
What is the impact of successful exploitation?
Successful exploitation can cause a denial of service through a null pointer dereference. The supplied CVSS vector indicates no confidentiality or integrity impact.
Which deployments are identified as affected?
The affected software listed is Microsoft Skype for Business Server Subscription Edition CU1, Skype for Business Server 2015 CU13, and Skype for Business Server 2019 CU8.