Microsoft Skype for Business Denial of Service Vulnerability
Released: Nov 13, 2018
- Assigning CNA
- Microsoft
- CVE.org link
- CVE-2018-8546
- Impact
- Denial of Service
- Max Severity
- Low
Executive Summary
A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability could cause Skype for Business to stop responding. Note that the denial of service would not allow an attacker to execute code or to elevate the attacker's user rights.
For an attack to be successful, this vulnerability requires that a user sends a number of emojis in the affected version of Skype for Business.
The security update addresses the vulnerability by correcting how Skype for Business handles emojis.
Exploitability
The following table provides an exploitability assessment for this vulnerability at the time of original publication.
- Publicly disclosed
- No
- Exploited
- No
- Exploitability assessment
- Exploitation Unlikely
Acknowledgements
- Sabine Degen of SEC Consult Vulnerability Lab
Security Updates
To determine the support lifecycle for your software, see the Microsoft Support Lifecycle.
- Security Update
- https://aka.ms/OfficeSecurityReleases
- Security Update
- -
- Security Update
- -
- Security Update
- https://aka.ms/OfficeSecurityReleases
- -
- -
- -
- -
Disclaimer
Revisions
Information published.