Skype for Business and Microsoft Lync
CVE-2018-8546 — Microsoft Skype for Business Denial of Service Vulnerability
Executive Summary
A denial of service vulnerability exists in Skype for Business. An attacker who successfully exploited the vulnerability could cause Skype for Business to stop responding. Note that the denial of service would not allow an attacker to execute code or to elevate the attacker's user rights. For an attack to be successful, this vulnerability requires that a user sends a number of emojis in the affected version of Skype for Business. The security update addresses the vulnerability by correcting how Skype for Business handles emojis.
Overview
Low
MS Severity
Not Exploited
MS Exploit Status
Exploitation Unlikely
MS Exploit Likelihood
EPSS Score
0.0546
probability of exploitation in the next 30 days
0.92034 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
12 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft Lync 2013 Service Pack 1 (32-bit) | 4461487 (Security Update) |
Low | Denial of Service | Maybe |
| Microsoft Lync 2013 Service Pack 1 (64-bit) | 4461487 (Security Update) |
Low | Denial of Service | Maybe |
| Microsoft Lync Basic 2013 Service Pack 1 (32-bit) | 4461487 (Security Update) |
Low | Denial of Service | Maybe |
| Microsoft Lync Basic 2013 Service Pack 1 (64-bit) | 4461487 (Security Update) |
Low | Denial of Service | Maybe |
| Microsoft Office 2019 for 32-bit editions | Click to Run (Security Update) |
Low | Denial of Service | No |
| Microsoft Office 2019 for 64-bit editions | Click to Run (Security Update) |
Low | Denial of Service | No |
| Office 365 ProPlus for 32-bit Systems | Click to Run (Security Update) |
Low | Denial of Service | No |
| Office 365 ProPlus for 64-bit Systems | Click to Run (Security Update) |
Low | Denial of Service | No |
| Skype for Business 2016 (32-bit) | 4461473 (Security Update) |
Low | Denial of Service | Maybe |
| Skype for Business 2016 (64-bit) | 4461473 (Security Update) |
Low | Denial of Service | Maybe |
| Skype for Business 2016 Basic (32-bit) | 4461473 (Security Update) |
Low | Denial of Service | Maybe |
| Skype for Business 2016 Basic (64-bit) | 4461473 (Security Update) |
Low | Denial of Service | Maybe |
Patches
3 patches
| Article | Type | Restart |
|---|---|---|
4461487 |
Security Update | Maybe |
Click to Run |
Security Update | No |
4461473 |
Security Update | Maybe |
Exploits & PoC
No public exploit or PoC has been linked for this CVE yet. When available, references are sourced from public repositories and may be unverified or non-functional — review carefully before use.
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
Sabine Degen of SEC Consult Vulnerability Lab
References
On This Page