CVE-2023-41763
Skype for Business Elevation of Privilege Vulnerability
Record summary
CVE-2023-41763 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template. CISA lists CVE-2023-41763 in KEV.
Description
Skype for Business Elevation of Privilege Vulnerability
Exploitation context
Known exploitation
- CISA KEV
- Listed · Oct 10, 2023 · CISA
- VulnCheck KEV
- Listed · Oct 10, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Skype for BusinessBrowse Microsoft / Skype for Business | CISA | Version data not supplied | |
Skype for Business Server 2015 CU13Browse Microsoft / Skype for Business Server 2015 CU13 | CVE List | 9319.0 to < 6.0.9319.869 | affected |
Skype for Business Server 2019 CU7Browse Microsoft / Skype for Business Server 2019 CU7 | CVE List | 2046.0 to < 7.0.246.530 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMSkype for Business 2019 (SfB) - Blind Server-side Request ForgeryCVSS 5.3
Skype Pre-Auth Server-side Request Forgery (SSRF) vulnerability
Impact
Unauthenticated attackers can exploit blind SSRF vulnerabilities through the meeturl parameter to make the Skype for Business server probe internal network resources, potentially discovering internal services and infrastructure topology.
Remediation
Apply Microsoft security patches for Skype for Business Server 2015 and 2019 that validate and restrict URL parameters in the LwaClient.aspx endpoint.
Source: ProjectDiscovery