CVE-2026-66302

9.8

Microsoft · Skype for Business Server

An unauthenticated remote code execution vulnerability exists in Skype for Business due to improper validation of user-controlled file paths.

Executive summary

A critical remote code execution vulnerability in Microsoft Skype for Business Server allows unauthenticated attackers to gain full control over affected systems.

Vulnerability

The flaw, classified under CWE-73, involves the external control of file names or paths. An unauthenticated attacker can leverage this to execute arbitrary code over the network.

Business impact

This vulnerability carries a CVSS score of 9.8, indicating a critical risk to organizational infrastructure. Successful exploitation allows an attacker to achieve full system compromise, leading to unauthorized access to sensitive communications, potential data exfiltration, and severe operational disruption.

Remediation

Immediate Action: Administrators must apply the security updates provided by Microsoft immediately. Ensure servers are upgraded to at least version 6.0.9319.885 for 2015 CU13, 7.0.2046.569 for 2019 CU8, or 7.0.2046.879 for Subscription Edition CU1.

Proactive Monitoring: Review server access logs for unusual file system activity or unexpected process execution patterns originating from external IP addresses.

Compensating Controls: Deploy Web Application Firewall rules to inspect and filter traffic for malicious file path traversal attempts or unexpected input strings targeting Skype services.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this remote code execution vulnerability and the lack of authentication required for exploitation, immediate patching is mandatory. Security teams should prioritize this update across all affected Skype for Business server environments to prevent potential system-wide compromise.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources