Vulnerabilities > Microsoft > Skype FOR Business > 2015

DATE CVE VULNERABILITY TITLE RISK
2020-07-14 CVE-2020-1025 Improper Input Validation vulnerability in Microsoft products
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation.
network
low complexity
microsoft CWE-20
critical
9.8
2019-01-17 CVE-2019-0624 Cross-site Scripting vulnerability in Microsoft Skype for Business 2015
A spoofing vulnerability exists when a Skype for Business 2015 server does not properly sanitize a specially crafted request, aka "Skype for Business 2015 Spoofing Vulnerability." This affects Skype.
network
low complexity
microsoft CWE-79
5.4