S4E just found a high-severity finding from [ai] pa ssl inspection control
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-41763 Scanner

CVE-2023-41763 Scanner - Server-Side-Request-Forgery vulnerability in Skype for Business

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
6.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-41763
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.
Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Skype for Business Server 2015 CU13by Microsoft
AFFECTED< 6.0.9319.869SAFE ✓≥ 6.0.9319.869
Skype for Business Server 2019 CU7by Microsoft
AFFECTED< 7.0.246.530SAFE ✓≥ 7.0.246.530
Updated Sep 10, 2026View on NVD →
Detail

Skype for Business is utilized by organizations to facilitate internal and external communication through instant messaging, voice, video calls, and online meetings. It enables seamless connectivity across various devices, offering integration with other Microsoft Office applications. Businesses primarily use Skype for Business for its comprehensive communication features, which include file transfers and whiteboard sessions. Many enterprises leverage this platform for its ability to support scalable communication solutions that align with corporate protocols. Skype for Business is a preferable choice due to its extensive security features, making it suitable for both small businesses and large enterprises. It is crucial for maintaining consistent and secure real-time communications within global organizations.

The Server-Side-Request-Forgery (SSRF) vulnerability allows an attacker to induce the server-side application to make HTTP requests to an unintended destination. This specific SSRF vulnerability, identified in Skype for Business 2019 with a medium CVSS score, permits external attackers to manipulate server actions. By exploiting this flaw, attackers can potentially bypass network defenses, leading to unauthorized network access or data disclosure. SSRF vulnerabilities are particularly dangerous since they can act as a stepping stone to gain further access to internal networks or sensitive data. In this vulnerability, malicious actors could create requests that the server would unwittingly execute on their behalf. Such vulnerabilities often arise from applications trusting unverified external input.

The vulnerability exploits the lack of proper input validation on the server-side, where the server indiscriminately processes crafted URLs. In this context, the vulnerability lies in the improper handling of base64 encoded inputs within the endpoint '/lwa/Webpages/LwaClient.aspx'. Utilizing the provided templates, an attacker can send a crafted payload disguised within legitimate requests to the server. When the server processes these maliciously crafted requests, it issues internal network requests as relayed by the attacker. Authentication is brackish, allowing attackers to pivot from SSRF to potential further exploits depending on service configurations. The exploitation does not require prior authorization, which expands its applicability and threat footprint in a network environment.

Exploiting this SSRF vulnerability can potentially lead to unauthorized actions taking place within the internal network, resulting in data exfiltration or server manipulation. Attackers could leverage such vulnerabilities to enumerate services and access internally facing endpoints. Furthermore, data theft or service disruption might occur if compounded with other vulnerabilities. It could lead to bypassing security controls designed to protect sensitive information or even launch further exploits. This vulnerability is critical as it can form a part of multi-stage attacks where attackers conduct preliminary reconnaissance. Additionally, it may provide a gateway for launching complex attacks, including internal DOS or unauthorized data manipulation campaigns.

REFERENCES

Solution Advice
  • Implement strict input validation and sanitization to ensure no unauthorized URLs are processed.
  • Limit the server’s ability to make outbound requests to predetermined and safe domains only.
  • Apply updates and patches provided by Microsoft to resolve known vulnerabilities.
  • Engage in regular network and application security audits to verify configurations.
  • Utilize web application firewalls with rules to detect and block potential SSRF attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.