CVE-2026-66303

Summary

Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftSkype for Business Server 2015 CU139319.0 < 6.0.9319.885affected
MicrosoftSkype for Business Server 2019 CU82046.0 < 7.0.2046.569affected
MicrosoftSkype for Business Server Subscription Edition CU12046.0 < 7.0.2046.879affected

Weaknesses

  • CWE-476: CWE-476: NULL Pointer Dereference

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References