Record summary

CVE-2023-41763 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template. CISA lists CVE-2023-41763 in KEV.

Description

Skype for Business Elevation of Privilege Vulnerability

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Oct 10, 2023 · CISA
VulnCheck KEV
Listed · Oct 10, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List9319.0 to < 6.0.9319.869affected
CVE List2046.0 to < 7.0.246.530affected

Nuclei templates

1
ProjectDiscoveryMEDIUMSkype for Business 2019 (SfB) - Blind Server-side Request ForgeryCVSS 5.3

Skype Pre-Auth Server-side Request Forgery (SSRF) vulnerability

Impact

Unauthenticated attackers can exploit blind SSRF vulnerabilities through the meeturl parameter to make the Skype for Business server probe internal network resources, potentially discovering internal services and infrastructure topology.

Remediation

Apply Microsoft security patches for Skype for Business Server 2015 and 2019 that validate and restrict URL parameters in the LwaClient.aspx endpoint.

Authorshateshape
Template tagscvecve2023skypeblind-ssrfoastssrfkevmicrosoftvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
Shodan: html:"Skype for Business"
Shodan: http.html:"skype for business"
FOFA: body="skype for business"

Source: ProjectDiscovery

References

3