← Vulnerability feed

Vulnerability record · CVE-2023-36789 · published 10 October 2023

CVE-2023-36789: Microsoft skype for business server code injection vulnerability

Microsoft · Skype For Business Server

Skype for Business Remote Code Execution Vulnerability

7.2 CVSS 3.1 High EPSS 2.4% · top 16.4% CWE-94 · Code injection
7.2CVSS 3.1 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Skype for Business Remote Code Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-36789 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.3CVE-2023-41763Microsoft Skype for Business Server SSRF Elevation of PrivilegeCVE-2023-41763 is a server-side request forgery (CWE-918) flaw in Microsoft Skype for Business Server, rated by Microsoft as an elevation of privileg…KEVEPSS 90%analysed9.8CVE-2026-66302Microsoft skype for business server vulnerabilityExternal control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network.EPSS 0.97%8.3CVE-2026-69646Microsoft skype for business server improper verification of cryptographic signature vulnerabilityImproper verification of cryptographic signature in Skype for Business allows an unauthorized attacker to perform spoofing over an adjacent network.EPSS 0.32%7.5CVE-2026-66307Microsoft skype for business server vulnerabilityInteger underflow (wrap or wraparound) in Skype for Business allows an unauthorized attacker to deny service over a network.EPSS 1.2%7.5CVE-2026-66304Microsoft skype for business server server-side request forgery (ssrf) vulnerabilityServer-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.EPSS 0.97%7.2CVE-2023-36780Microsoft skype for business server untrusted search path vulnerabilitySkype for Business Remote Code Execution VulnerabilityEPSS 2.6%7.2CVE-2023-36786Microsoft skype for business server vulnerabilitySkype for Business Remote Code Execution VulnerabilityEPSS 2.5%7.2CVE-2021-26422Microsoft lync server vulnerabilitySkype for Business and Lync Remote Code Execution VulnerabilityEPSS 2.2%

Source: NIST National Vulnerability Database (record CVE-2023-36789), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.