CVE-2019-1490 is a medium-severity spoofing vulnerability affecting Microsoft Skype for Business Server. It arises from improper sanitization of specially crafted requests, allowing an authenticated attacker to potentially spoof content. The attack requires user interaction and has low impact on confidentiality and integrity, with no impact on availability. There is no public exploit code, nor is it known to be actively exploited, and it has received minimal community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:skype_for_business:2019:cumulative_update_2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.