CVE-2026-66302

Summary

External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftSkype for Business Server 2015 CU139319.0 < 6.0.9319.885affected
MicrosoftSkype for Business Server 2019 CU82046.0 < 7.0.2046.569affected
MicrosoftSkype for Business Server Subscription Edition CU12046.0 < 7.0.2046.879affected

Weaknesses

  • CWE-73: CWE-73: External Control of File Name or Path

References