CVE-2019-1029 is a denial of service vulnerability affecting Microsoft Skype for Business and Lync Server. An attacker could exploit this by obtaining a dial-in link and initiating rapid, successive calls, causing the server to become unresponsive. This vulnerability has a CVSS score of 5.9 (Medium) due to its network attack vector and high impact on availability, though it requires high attack complexity and does not allow code execution or privilege escalation. There is no public exploit code available, it is not actively exploited, and it has received limited community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:lync_server:2010:*:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:lync_server:2013:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.