Important EPSS 0.04937 📢 Publicly disclosed 2019-05 archive

Executive Summary

An information disclosure vulnerability exists in Skype for Android. An attacker that exploited the vulnerability could listen to the conversation of a Skype for Android user without the user’s knowledge. To exploit the vulnerability, an attacker would need to call an Android phone with Skype for Android installed that’s also paired with a Bluetooth device. The security update addresses the vulnerability by correcting how Skype for Android answers incoming calls.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Information Disclosure
Released May 14 2019
Last Updated May 14 2019
Publicly Disclosed Yes
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.04937 — 0.91029 percentile

EPSS Score

0.04937
probability of exploitation in the next 30 days
0.91029 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Skype 8.35 when installed on Android Devices Important Information Disclosure Unknown

Patches

1 patch
Article Type Restart
Unknown

Known Exploits

Acknowledgments

Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.