CVE-2026-69642: Skype for Business Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Skype for Business allows an unauthorized attacker to perform spoofing over a network.
Other sources
Skype for Business Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.9319.885Patch KB5123301 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.2046.879Patch KB5123287 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.2046.569Patch KB5123300
Event History
Frequently Asked Questions
Which deployments should be prioritized for review?
Review Microsoft Skype for Business Server 2015 CU13, Skype for Business Server 2019 CU8, and Skype for Business Server Subscription Edition CU1. The provided data identifies these specific releases as affected.
Does exploitation require an authenticated account or user interaction?
No. The supplied CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What impact is indicated if the issue is exploited?
The CVSS vector indicates low confidentiality and integrity impact, with no availability impact. The vulnerability is categorized as cross-site scripting and is described as enabling spoofing.