SB2023101033 - Information disclosure in Skype for Business server



SB2023101033 - Information disclosure in Skype for Business server

Published: October 10, 2023

Security Bulletin ID SB2023101033
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2023-41763)

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can gain unauthorized access to IP addresses or port numbers or both to the attacker.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install update from vendor's website.