4.3
CVSSv2

CVE-2017-8550

Published: 15/06/2017 Updated: 19/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.2
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft office 2016

Exploits

# Exploit Title: Skype for Business 2016 XSS Injection - CVE-2017-8550 # # Exploit Author: @nyxgeek - TrustedSec # Date: 2017-04-10 # Vendor Homepage: wwwmicrosoftcom # Versions: 16078301018 32-bit & 16079271020 64-bit or lower # # # Requirements: Originating machine needs Lync 2013 SDK installed as well as a user logged # into the S ...

Github Repositories

my public exploit code

exploits and CVE listing my public exploit code CVE-2017-8550 - Microsoft Skype for Business 2016 (aka Lync) wwwexploit-dbcom/exploits/42316 msrcmicrosoftcom/update-guide/en-us/vulnerability/CVE-2017-8550 POC: wwwyoutubecom/watch?v=oGcGVDM7fuk CVE-2018-8474 - Microsoft Lync 2011 for Mac wwwexploit-dbcom/exploits/45936 msrcmicr