VulnerabilityModified
CVE-2018-8546
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.
MEDIUM 5.9EPSS 5.46%
Does this matter?
Lower severity and a low EPSS score (5.46%). Track it; it rarely justifies an emergency change on its own.
Description
A denial of service vulnerability exists in Skype for Business, aka "Microsoft Skype for Business Denial of Service Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Lync, Skype.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 5.46% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/lync · microsoft/lync basic · microsoft/office · microsoft/office 365 proplus · microsoft/skype for business · microsoft/skype for business basic
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/105802Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042125Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8546Patch, Vendor Advisory
- http://www.securityfocus.com/bid/105802Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042125Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8546Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.