Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-8546

24
FAUCET Score

CVE-2018-8546 is a denial of service vulnerability affecting Microsoft Skype for Business, Lync, and Office 365 ProPlus. With a CVSS score of 5.9 (Medium), this vulnerability can be exploited remotely with high attack complexity, leading to a complete denial of service without requiring user interaction. While its EPSS score is relatively low, indicating a lower likelihood of exploitation, there are no known public exploits or Metasploit modules available. Community discussion and media coverage are minimal, suggesting it is not currently a high-profile threat.

Impacted Technologies

VendorProductVersion(s)CPE
2013CPE matchmatch criteria
cpe:2.3:a:microsoft:lync:2013:sp1:*:*:*:*:*:*
2013CPE matchmatch criteria
cpe:2.3:a:microsoft:lync_basic:2013:sp1:*:*:*:*:*:*
2019CPE matchmatch criteria
cpe:2.3:a:microsoft:office:2019:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:microsoft:office_365_proplus:-:*:*:*:*:*:*:*
2016CPE matchmatch criteria
cpe:2.3:a:microsoft:skype_for_business:2016:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.9MEDIUM

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
5.46%
Probability of exploitation in next 30 days
EPSS Percentile
91.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0546 is in the 90th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

microsoftpatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Skype for Business 2016 (32-bit)
View patch
microsoftpatch availablevia msrc
Product: Skype for Business 2016 Basic (32-bit)
View patch
microsoftpatch availablevia msrc
Product: Skype for Business 2016 (64-bit)
View patch
microsoftpatch availablevia msrc
Product: Skype for Business 2016 Basic (64-bit)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Lync 2013 Service Pack 1 (32-bit)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Lync Basic 2013 Service Pack 1 (32-bit)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Lync 2013 Service Pack 1 (64-bit)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Lync Basic 2013 Service Pack 1 (64-bit)
View patch
microsoftpatch availablevia msrc
Product: Microsoft Office 2019 for 32-bit editionsFixed in: https://aka.ms/OfficeSecurityReleases
microsoftpatch availablevia msrc
Product: Microsoft Office 2019 for 64-bit editionsFixed in: https://aka.ms/OfficeSecurityReleases
microsoftpatch availablevia msrc
Product: Office 365 ProPlus for 32-bit Systems
microsoftpatch availablevia msrc
Product: Office 365 ProPlus for 64-bit Systems

Vendor Advisories (1)

microsoft2018-Nov/CVE-2018-8546Low

Microsoft Skype for Business Denial of Service Vulnerability

Nov 13, 2018

References

portal.msrc.microsoft.com / en-US/security-guidance/advisory/CVE-2018-8546
PatchVendor Advisory
securityfocus.com / bid/105802
Third Party AdvisoryVDB Entry
securitytracker.com / id/1042125
Third Party AdvisoryVDB Entry