CVE-2022-33633 is a high-severity Remote Code Execution (RCE) vulnerability affecting Microsoft Skype for Business and Lync Server. An attacker with high privileges can exploit this vulnerability over the network with low attack complexity, leading to high impact on confidentiality, integrity, and availability. While not actively exploited in the wild (not in KEV), there is no public exploit code (Metasploit, Nuclei, ExploitDB), and community discussion is minimal, though it was mentioned in a BleepingComputer article regarding Microsoft's July 2022 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:lync_server:2013:cumulative_update_10:*:*:*:*:*:* | ||
2015CPE matchmatch criteria | cpe:2.3:a:microsoft:skype_for_business:2015:cumulative_update_12:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:skype_for_business:2019:cumulative_update_6:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.