CVE-2026-66306: Skype for Business Information Disclosure Vulnerability
Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.
Other sources
Skype for Business Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.9319.885Patch KB5123301 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.2046.879Patch KB5123287 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.2046.569Patch KB5123300
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The vector is network-based and no privileges are required. Exploitation requires user interaction.
What is the expected impact if the vulnerability is exploited?
An unauthorized attacker may disclose sensitive information. The provided severity data indicates confidentiality impact is high, with no stated integrity or availability impact.
Which deployments are identified as affected?
The affected software listed is Microsoft Skype for Business Server 2015 CU13, Skype for Business Server Subscription Edition CU1, and Skype for Business Server 2019 CU8.