CVE-2021-24099 is a denial-of-service vulnerability affecting Microsoft Skype for Business and Lync servers. With a CVSS score of 6.5 (Medium), it can be exploited remotely with low complexity by an authenticated attacker, leading to a complete denial of service without impacting confidentiality or integrity. While it has a low EPSS score and is not on the KEV catalog, there is no public exploit code available, and it has received minimal community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:lync_server:2013:*:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:microsoft:skype_for_business_server:2015:cu8:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:skype_for_business_server:2019:cu2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.