CVE-2022-26911 is an information disclosure vulnerability affecting Microsoft Skype for Business Server and Lync Server. With a CVSS score of 6.5 (Medium), it allows an authenticated attacker to remotely disclose sensitive information with low attack complexity. While not currently listed on CISA's KEV catalog, there is no public exploit code available, and community discussion and media coverage have been minimal, with only one article mentioning it in the context of Microsoft's April 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:lync_server:2013:cumulative_update_10:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:microsoft:skype_for_business_server:2015:cu12:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:skype_for_business_server:2019:cu6:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.