peter bassill · operator
$ cve CVE-2017-8550 JSON

CVE-2017-8550 EXPLOIT

5.4
MEDIUM · CVSS 3.0 · EPSS 22.4% (pctl 98)

Patch early

A public exploit exists.

Description

A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".

Scoring

CVSS5.4 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
EPSS22.43% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2017-06-15
Last modified2026-06-17

Affected (1)

VendorProduct
microsoftoffice

Public exploits

SourceTitleDate
exploit-dbSkype for Business 2016 - Cross-Site Scripting2017-07-12

References

→ the Explorer  ·  watch your stack  ·  NVD