External risk intelligence

Skype for Business Network Code Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-66302

Skype for Business is a communication application typically deployed within internal corporate environments. While it can be configured for remote access or external federation, it is not primarily designed as a public-facing internet service like a web portal or edge gateway, making internet-wide exposure possible but not the standard deployment pattern.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Skype for Business could allow unauthorized attackers to execute code over a network by manipulating file names. This issue is particularly concerning due to the potential for remote code execution, which attackers could leverage to compromise systems. The primary concern for leadership is to confirm if this technology is in use and assess potential exposure.

  • Attackers can run unauthorized code remotely.
  • Critical flaw impacts business communication systems.
  • Confirm relevance and potential exposure immediately.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted network request to a vulnerable Skype for Business instance. This request targets a weakness in how the application handles file names or paths, allowing the attacker to potentially execute arbitrary code on the server. Successful exploitation could lead to a complete compromise of the affected system, enabling an attacker to perform unauthorized actions over a network.

  • No authentication or privileges needed.
  • Network request with malicious file path.
  • Remote code execution and system compromise.

Live Threat

Current exploitation, exposure, and threat context

An attacker could execute code over a network by manipulating file names or paths in Skype for Business, when supported by the advisory's described conditions. This could allow for unauthorized code execution, impacting the confidentiality, integrity, and availability of the affected system.

  • Code execution on the system.
  • Exploiting file path vulnerabilities.
  • Compromised system confidentiality and integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Skype for Business, allowing network code execution via external control of file paths, likely falls under the responsibility of the platform or infrastructure teams managing the application, in coordination with the vendor management team for patching or updates. The immediate first step is to identify all Skype for Business deployments, confirm their network exposure and business criticality, and then assign an accountable owner to prioritize and plan remediation based on assessed risk.

  • Platform and infrastructure teams own resolution.
  • Verify network exposure and business criticality.
  • Plan coordinated updates and mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Skype for Business?

Skype for Business is a communication platform designed for enterprise environments, enabling users to participate in instant messaging, voice calls, and video conferencing. It functions as a central hub for organizational collaboration, typically integrated into internal corporate networks to facilitate professional connectivity and shared workspaces.

What does CWE-73 mean for CVE-2026-66302?

CWE-73 refers to the external control of file name or path. In this vulnerability, it means the application does not properly validate or sanitize file paths provided in network requests. By manipulating these paths, an attacker can influence how the software interacts with the file system, potentially leading to unauthorized code execution.

How is this vulnerability triggered?

An attacker triggers the flaw by sending a specially crafted network request to the application that contains a malicious file name or path. It is important to note that the vulnerability is not triggered by standard user interactions like simply sending messages or joining a legitimate conference; it requires specifically manipulated data designed to exploit the path handling weakness.

Is my Skype for Business deployment at risk?

Halo Surface Signal indicates that while this software is usually deployed internally, it can be configured for remote access or external federation. Systems accessible over the internet are at higher risk. You should evaluate your specific network architecture to determine if your instance is reachable from outside your corporate environment.

How should I respond to this CVE?

Your first step is to identify all instances of Skype for Business across your organization. Once identified, work with your infrastructure teams to verify the network connectivity of each server. After assessing the business criticality and exposure of these systems, coordinate with your vendor management team to apply the necessary security updates provided by the software manufacturer.

References