CVE-2017-8550 is a remote code execution vulnerability in Microsoft Skype for Business, stemming from insufficient sanitization of specially crafted content. With a CVSS score of 5.4 (Medium), this vulnerability requires high attack complexity and has the potential for limited confidentiality and integrity impact, but no availability impact. While no active exploitation is confirmed and no public exploit code exists for RCE, a Cross-Site Scripting exploit for Skype for Business 2016 is available on ExploitDB. The vulnerability has garnered minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:office:2016:*:*:*:click-to-run:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.