CVE-2019-0798: Microsoft Lync Server

Medium severity, CVSS 6.1. EPSS: 2.1% chance of exploitation in the next 30 days.

A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'.

Affected products

  • Microsoft Lync Server: version 2013 only
  • Microsoft Skype For Business Server: version 2015 only

Published 2019-04-09. Last modified 2026-06-17.