CVE-2021-24073 is a spoofing vulnerability affecting Microsoft Skype for Business and Lync servers. With a CVSS score of 7.1 (HIGH), it allows an unauthenticated attacker to achieve high confidentiality impact and low integrity impact through a low-complexity network attack requiring user interaction. While not currently listed in CISA's KEV catalog, there is no public exploit code available, nor is it actively exploited. Despite this, it has received some community attention and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:lync_server:2013:*:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:microsoft:skype_for_business_server:2015:cu8:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.